vendor:
Cyberoam NG Firewall
by:
Dharmendra Kumar Singh
N/A
CVSS
N/A
SQL Injection
89
CWE
Product Name: Cyberoam NG Firewall
Affected Version From: CR500iNG-XP - 10.6.2 MR-1
Affected Version To: CR500iNG-XP - 10.6.2 MR-1
Patch Exists: YES
Related CWE: N/A
CPE: a:cyberoam:cyberoam_ng_firewall
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Cyberoam : Blind SQL Injection
The username field in the captive portal of Cyberoam NG firewall is vulnerable to SQL Injection and can be exploited to execute sql commands on the database. The username field is vulnerable to the following types of SQL Injections: a) Boolean-based blind sql injection b) Stacked queries.
Mitigation:
Input validation should be done on the username field to prevent SQL Injection.