7.5
CVSSv2

CVE-2002-0709

Published: 10/10/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote malicious users to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs.

Vulnerable Product Search on Vulmon Subscribe to Product

surfcontrol superscout web filter 3.0

surfcontrol superscout web filter 3.0.3

surfcontrol web filter 4.0

surfcontrol web filter 4.1

Exploits

source: wwwsecurityfocuscom/bid/5859/info SurfControl SuperScout WebFilter Reports Server is prone to SQL injection attacks This issue is due to insufficient input validation on the part of some of the reports files, which are implemented as dlls As a consequence, remote attackers are able to modify the logic of SQL queries This may ...