HTTP: SQL Injection Detected on HTTP Request Variable 1

This signature detects specific characters, typically used in SQL procedures, within an HTTP connection. Because these characters are not normally used in HTTP, this can indicate a SQL injection attack through a procedure. However, it can be a false positive. To reduce False Positives, it is strongly recommended that these signatures only be used to inspect traffic from the Internet to your organization's web servers that use SQL backend databases to generate content and not to inspect traffic going from your organization to the Internet.

Extended Description

Multiple SQL injection vulnerabilities in MYRE Vacation Rental Software allow remote attackers to execute arbitrary SQL commands via the (1) garage1 or (2) bathrooms1 parameter to vacation/1_mobile/search.php, or (3) unspecified input to vacation/widgate/request_more_information.php.

Affected Products

Myrephp myre_vacation_rental

Short Name
HTTP:SQL:INJ:REQ-VAR-1
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
1 CVE-2008-5191 CVE-2010-0722 CVE-2010-0970 CVE-2010-0974 CVE-2010-1269 CVE-2010-1270 CVE-2010-1538 CVE-2010-1855 CVE-2010-1924 CVE-2010-2720 CVE-2010-4273 CVE-2010-4846 CVE-2010-4911 CVE-2012-2908 CVE-2012-5288 CVE-2012-6516 CVE-2012-6586 CVE-2013-4467 CVE-2013-4468 CVE-2013-5120 CVE-2013-5121 CVE-2014-10034 CVE-2014-3828 CVE-2015-2562 CVE-2017-12710 Detected HTTP Injection Request SQL Variable bid:38649 bid:63288 bid:63340 on
Release Date
03/02/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Rarely
Vendors

Myrephp

CVSS Score

7.5

6.5

10.0

5.0

Found a potential security threat?