Contact Us  |  How To Buy  |  Worldwide  |  Careers  |  Login

Attack Signature Detail 

SQL-Inj-POST-SP_ADDLGN

ID: 9768    
Protected since: 12/9/2008 12:00:00 AM    
File version: 0009_0013_00 Low:
Download File
Click here to download the complete Signature File that includes this attack

Alias 
Affected systems
DetailsSQL Injection - POST-SP_ADDLGN
ImpactInformation disclosure Information compromise Denial of Service
Attack vectorAny protocol that has affect on an SQL Servers. (most common is TCP port 80 - HTTP)
Recommended solutionSQL-Inj-POST-SP_ADDLGN protects against an SQL injection attack. SQL injections occur due to an application improperly sanitizing user-supplied input. An attacker is able to exploit this vulnerability by providing specially constructed user-supplied input which will alter the SQL statement of the application, executing arbitrary SQL statements on the database server. This may result in sensitive information disclosure, information compromise and database denial of service. Recommended Solutions In order to protect against SQL injections the following steps should be taken: - Update your Radware device with the latest signature file (See the supported products list below). - Ensure that the 'SQL Injection' group exists in the active protection profile.
References
Radware ID9768
Radware groupSQL_Injection-Advan
ApplicationsDBMS - Microsoft SQL,DBMS - MySQL,DBMS - Oracle,DBMS - Others
ServicesHTTP
RiskInfo
ConfidenceLow
Threat typeIntrusions
Minimum application security version2.21.01
Hardware requirementsSME