Short Name |
HTTP:SQL:INJ:SYNDEO-CMS-USRNAME |
---|---|
Severity |
Minor |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
SyndeoCMS SQL Injection Vulnerability |
Release Date |
2011/03/31 |
Update Number |
1892 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known SQL Injection vulnerability in SyndeoCMS content manager. An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
SyndeoCMS is prone to multiple cross-site scripting vulnerabilities and an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. SyndeoCMS 2.8.02 is vulnerable; other versions may also be affected.