HTTP: SQL AUTHID Keyword SQL Injection

This signature detects attempts to run SQL queries with high privileges. The AUTHID CURRENT_USER keyword can be used to run queries with privileges of the owner. It can also be a false positive. To reduce False Positives, it is strongly recommended that these signatures only be used to inspect traffic from the Internet to your organization's web servers that use SQL backend databases to generate content and not to inspect traffic going from your organization to the Internet.

Extended Description

Injection of the AUTHID CURRENT_USER SQL directive by an attacker may escalate privilege levels and allow an attacker access to database objects that would otherwise be inaccessible under the definer rights model.

Short Name
HTTP:SQL:INJ:AUTHID
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
AUTHID Injection Keyword SQL
Release Date
03/03/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?