Security Portal

Intrusion Prevention Service

Signature Version: 4.990


WEB SQL injection attempt -33
Threat Level: High
Release Date: 2014/3/28
Category: Web Attacks
Signature ID: 1059160
Included In:
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix
Description: SQL injection is a vulnerability that allows an attacker to alter backend SQL statements by manipulating the user input. An SQL injection occurs when web applications accept user input that is directly placed into a SQL statement and doesn't properly filter out dangerous characters.
Impact: SQL injection
Recommendation: Validate all input in web application
False Positive: None
False Negative: None
Additional Information (Links open in new window):
Reference(s): OSVDB-98232; CVE-2016-unknown; msf; Struts2 s2-041

Search the Threat Database
Enter Rule ID or Name