Security Portal

Intrusion Prevention Service

 
Signature Version: 4.938

 



WEB SQL injection attempt -7
 
Threat Level: Critical
Release Date: 2011/6/9
 
Category: Web Attacks
Signature ID: 1054841
Included In:
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix
 
Description: SQL injection is a vulnerability that allows an attacker to alter backend SQL statements by manipulating the user input. An SQL injection occurs when web applications accept user input that is directly placed into a SQL statement and doesn't properly filter out dangerous characters.
 
Impact: SQL injection
Recommendation: Validate all input in web application
 
False Positive: None
False Negative: None
 
Additional Information (Links open in new window):
Reference(s): CVE-2010-0112; CVE-2013-7278; ZDI-17-128; CVE-2017-5810; CVE-2017-5811
 

Search the Threat Database
Enter Rule ID or Name