[] NeoSense

SurfControl SuperScout WebFilter for Windows 2000 - SQL Injection

Author: Matt Moore
type: remote
platform: windows
port: 
date_added: 2002-10-02 
date_updated: 2012-10-11 
verified: 1 
codes: CVE-2002-0709;OSVDB-3494 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/5859/info

SurfControl SuperScout WebFilter Reports Server is prone to SQL injection attacks. This issue is due to insufficient input validation on the part of some of the reports files, which are implemented as .dlls.

As a consequence, remote attackers are able to modify the logic of SQL queries. This may result in database corruption or disclosure of sensitive information.

http://reports-server:8888/SimpleBar.dll/RunReport ?...<various parameters>