HTTP.URI.SQL.Injection

Last Updated DateMay 28, 2009
Release DateJun 10, 2008
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attempt to exploit an SQL-injection vulnerability through HTTP requests.

The vulnerability is a result of the application's failure to check user input before using it in an SQL query. As a result, a remote attacker can send a crafted query to execute SQL commands on a vulnerable server.
Affected ProductsThis is a generic signature against web-based SQL injections.
Recommended ActionsApply the latest patch to the vulnerable software.
Reference: VID-15621