Contact Us
|
How To Buy
|
Worldwide
|
Careers
|
Login
Home
Solutions
Enterprise
Data Center
Applications
Security
WAN Optimization
Cloud Computing
Industries
Carrier & Service Provider
Mobile Internet
Managed Security
DPI/DFI
VoIP/SIP ADC
Cloud Computing
OSS/BSS
Products
Application Delivery
AppDirector
Alteon
AppWall
AppXML
AppXcel
VirtualDirector
SIP Director
LinkProof
Content Inspection Director
vAdapter
Application and Network Security
DefensePro
Security Zone
Real-time Intelligence
Inflight
Management
APSolute Vision
Company
Management
Investor Relations
SEC Filings
Financials
Annual Reports
Customers
Technology Alliances
Industry Expertise
Careers
Israel (International HQ)
Americas (North & South)
Europe Middle East Africa (EMEA)
Asia Pacific (APAC)
Locations
News & Events
Press Releases
Media Coverage
Events
Awards
Certifications
Media Kit
Customer
Technical Support
Training
Schedules & Registration
Course Descriptions
Tuition & Fees
Certification
Additional Training Resources
Security Zone
Threats
Latest Attack Signatures
Latest WAF Updates
Signature Database
Security Update Service
Emergency Response Team
Partner
Partner Program
Marketing
Training
Become a Partner
Find a Partner
Technical Support
Training
Security Zone
Threats
Latest Attack Signatures
Latest WAF Updates
Signature Database
Security Update Service
Emergency Response Team
Attack Signature Detail
SQL-Inj-GET-SP_ADDLGN
ID:
9766
Protected since:
12/9/2008 12:00:00 AM
File version:
0009_0013_00
Low:
Click here to download the complete Signature File that includes this attack
Alias
Affected systems
Details
SQL Injection - GET-SP_ADDLGN
Impact
Information disclosure Information compromise Denial of Service
Attack vector
Any protocol that has affect on an SQL Servers. (most common is TCP port 80 - HTTP)
Recommended solution
SQL-Inj-GET-SP_ADDLGN protects against an SQL injection attack. SQL injections occur due to an application improperly sanitizing user-supplied input. An attacker is able to exploit this vulnerability by providing specially constructed user-supplied input which will alter the SQL statement of the application, executing arbitrary SQL statements on the database server. This may result in sensitive information disclosure, information compromise and database denial of service. Recommended Solutions In order to protect against SQL injections the following steps should be taken: - Update your Radware device with the latest signature file (See the supported products list below). - Ensure that the 'SQL Injection' group exists in the active protection profile.
References
Radware ID
9766
Radware group
SQL_Injection-Advan
Applications
DBMS - Microsoft SQL,DBMS - MySQL,DBMS - Oracle,DBMS - Others
Services
HTTP
Risk
Info
Confidence
Low
Threat type
Intrusions
Minimum application security version
2.00.00
Hardware requirements
SME
©
Radware Ltd. 2010 All Rights Reserved.
Sitemap
|
Privacy Policy
|
Site Feedback
|
Terms of Use
|
Glossary
Smart Network. Smart Business. ™