Imperva SecureSphere - SQL injection filter bypass
Affected Software : SecureSphere Web Application Firewall (WAF)
Severity : High
Local/Remote : Remote
Author : @drk1wi
Summary
Due to a typo in one of the rules of the sql injection engine the WAF can be bypassed by appending a specially crafted string.
Vulnerability Details
The vector: 15 and '1'=(SELECT '1' FROM dual) and '0having'='0having' won't be classified as malicious and will bypass the SQL Injection filter. 'and '0having'='0having' is causing the bypass.
Time-line
8/07/2010 - Vendor notified
10/07/2010 - Vendor response
12/08/2010 - Vendor patch release
06/05/2011 - Public disclosure
Home
»
»Unlabelled
» Imperva SecureSphere - SQL injection filter bypass
Recent Posts
IDM Internet Download Manager 6.19 Build 8 Serial Keys Free Download
10 May 20140IDM Internet Download Manager 6.19 Build 8 Serial Keys DownloadIDM Internet Download Manager 6.19 Bu...Read more »
IDM 6.19 Build 8 Keys - Download Internet Download Manager Serial Key
30 Apr 20140IDM 6.19 Build 8 Keys - Download Internet Download Manager Serial KeyIDM 6.19 Build 8 Keys - Downloa...Read more »
IDM 6.19 Build 8 Crack - Download Internet Download Manager Crack
29 Apr 20140IDM 6.19 Build 8 Crack - Download Internet Download Manager CrackIDM 6.19 Build 8 Crack - Download I...Read more »
IDM Internet Download Manager 6.19 Build 7 Serial Keys Download
28 Apr 20140IDM Internet Download Manager 6.19 Build 7 Serial Keys DownloadIDM Internet Download Manager 6.19 Bu...Read more »
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment
WELLCOME MY WEB
Click to see the code!
To insert emoticon you must added at least one space before the code.