Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:SQL:INJ:CMD-IN-URL

Severity

Medium

Recommended

No

Category

HTTP

Keywords

SQL Command in URL

Release Date

2004/05/26

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: SQL Command in URL


This signature detects a SQL command in a URL. Because SQL commands are not normally used in HTTP connections, this can indicate a SQL injection attack. This can also be a false positive. To reduce false positives, it is strongly recommended that these signatures only be used to inspect traffic from the Internet to your organization's Web servers that use SQL backend databases to generate content and not to inspect traffic going from your organization to the Internet.

Extended Description

Netscape's iPlanet iCal application is a network based calendar service built for deployment in organizations which require a centralized calendar system. Certain versions of iCal ship with a vulnerability introduced in the installation process which will allow malicious local users to gain root on the system. During the installation process a large number of files are left world readable and writable. One such file, /opt/SUNWicsrv/cal/bin/iplncal.sh is designed to be run at startup as root and is world writable by default. This allows users to modify the contents of this startup script and have it executed at boot up time or whenever the machine is re-initialized.

Affected Products

  • Netscape iCal 2.1.0 Patch2

References

  • BugTraq: 67754
  • BugTraq: 22593
  • BugTraq: 1768
  • BugTraq: 66302
  • CVE: CVE-2015-1605
  • CVE: CVE-2011-4340
  • CVE: CVE-2014-1651
  • CVE: CVE-2000-0402
  • CVE: CVE-2014-2587

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out