HTTP: PHP Code Injection In HTTP Requests

This signature detects the attempts of injection of PHP code in the HTTP requests.

Extended Description

The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data.

Affected Products

Symantec web_gateway

References

CVE: CVE-2012-2957

Short Name
HTTP:URI-PHP-INJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2012-2957 Code HTTP In Injection PHP Requests
Release Date
09/27/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3675
False Positive
Unknown
Vendors

Symantec

CVSS Score

7.2

Found a potential security threat?