CVE-2020-4575
published 2020-08-27CVE-2020-4575: IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability…
PriorityP424medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.92%
56.6th percentile
IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | >= 8.5.0.0 < 8.5.5.18 | 8.5.5.18 |
| ibm | websphere_application_server | >= 9.0.0.0 < 9.0.5.5 | 9.0.5.5 |
| ibm | websphere_application_server_nd | — | — |
| ibm | websphere_application_server_nd | — | — |
| ibm | websphere_virtual_enterprise | — | — |
| ibm | websphere_virtual_enterprise | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv3.04.7MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language UNION SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language UNION SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"language="; nocase; content:"UNION"; nocase; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006034; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, m
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id ASCII
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id ASCII"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"id="; nocase; content:"SELECT"; nocase; pcre:"/ASCII\(.+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006031; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"lastname="; nocase; content:"SELECT"; nocase; pcre:"/SELECT.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006003; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language DELETE
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language DELETE"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"language="; nocase; content:"DELETE"; nocase; pcre:"/DELETE.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006036; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass INSERT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass INSERT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"newuserPass="; nocase; content:"INSERT"; nocase; pcre:"/INSERT.+INTO/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006047; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter UNION SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter UNION SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"defaultLetter="; nocase; content:"UNION"; nocase; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006040; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name In
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php firstname UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php firstname UNION SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php firstname UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php firstname UNION SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"firstname="; nocase; content:"UNION"; nocase; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006010; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo ASCII
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo ASCII"; flow:established,to_server; http.uri; content:"/search.php?"; nocase; content:"goTo="; nocase; content:"SELECT"; nocase; pcre:"/ASCII\(.+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006067; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter ASCII
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter ASCII"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"defaultLetter="; nocase; content:"SELECT"; nocase; pcre:"/ASCII\(.+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006043; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail UNION SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail UNION SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"newuserEmail="; nocase; content:"UNION"; nocase; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006058; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initi
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search UPDATE
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search UPDATE"; flow:established,to_server; http.uri; content:"/search.php?"; nocase; content:"search="; nocase; content:"UPDATE"; nocase; pcre:"/UPDATE.+SET/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006074; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass UNION SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass UNION SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"newuserPass="; nocase; content:"UNION"; nocase; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006046; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"language="; nocase; content:"SELECT"; nocase; pcre:"/SELECT.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006033; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo UNION SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo UNION SELECT"; flow:established,to_server; http.uri; content:"/search.php?"; nocase; content:"goTo="; nocase; content:"UNION"; nocase; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006064; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_t
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass DELETE
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass DELETE"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"newuserPass="; nocase; content:"DELETE"; nocase; pcre:"/DELETE.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006048; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo SELECT"; flow:established,to_server; http.uri; content:"/search.php?"; nocase; content:"goTo="; nocase; content:"SELECT"; nocase; pcre:"/SELECT.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006063; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php passwordOld INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php passwordOld INSERT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php passwordOld INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php passwordOld INSERT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"passwordOld="; nocase; content:"INSERT"; nocase; pcre:"/INSERT.+INTO/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006017; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search SELECT"; flow:established,to_server; http.uri; content:"/search.php?"; nocase; content:"search="; nocase; content:"SELECT"; nocase; pcre:"/SELECT.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006069; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search DELETE
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search DELETE"; flow:established,to_server; http.uri; content:"/search.php?"; nocase; content:"search="; nocase; content:"DELETE"; nocase; pcre:"/DELETE.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006072; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id UNION SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id UNION SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"id="; nocase; content:"UNION"; nocase; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006028; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserType ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserType ASCII
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserType ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserType ASCII"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"newuserType="; nocase; content:"SELECT"; nocase; pcre:"/ASCII\(.+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006055; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitr
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"defaultLetter="; nocase; content:"SELECT"; nocase; pcre:"/SELECT.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006039; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access,
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname UPDATE
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname UPDATE"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"lastname="; nocase; content:"UPDATE"; nocase; pcre:"/UPDATE.+SET/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006008; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id INSERT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id INSERT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"id="; nocase; content:"INSERT"; nocase; pcre:"/INSERT.+INTO/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006029; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo UPDATE
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo UPDATE"; flow:established,to_server; http.uri; content:"/search.php?"; nocase; content:"goTo="; nocase; content:"UPDATE"; nocase; pcre:"/UPDATE.+SET/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006068; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- save.php groupAddName ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- save.php groupAddName ASCII
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- save.php groupAddName ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- save.php groupAddName ASCII"; flow:established,to_server; http.uri; content:"/save.php?"; nocase; content:"groupAddName="; nocase; content:"SELECT"; nocase; pcre:"/ASCII\(.+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006079; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, m
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- save.php groupAddName INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- save.php groupAddName INSERT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- save.php groupAddName INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- save.php groupAddName INSERT"; flow:established,to_server; http.uri; content:"/save.php?"; nocase; content:"groupAddName="; nocase; content:"INSERT"; nocase; pcre:"/INSERT.+INTO/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006077; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mi
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname INSERT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname INSERT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"lastname="; nocase; content:"INSERT"; nocase; pcre:"/INSERT.+INTO/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006005; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search UNION SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search UNION SELECT"; flow:established,to_server; http.uri; content:"/search.php?"; nocase; content:"search="; nocase; content:"UNION"; nocase; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006070; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, m
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname DELETE
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname DELETE"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"lastname="; nocase; content:"DELETE"; nocase; pcre:"/DELETE.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006006; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter DELETE
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter DELETE"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"defaultLetter="; nocase; content:"DELETE"; nocase; pcre:"/DELETE.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006042; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access,
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname ASCII
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname ASCII"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"lastname="; nocase; content:"SELECT"; nocase; pcre:"/ASCII\(.+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006007; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniq
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserType INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserType INSERT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserType INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserType INSERT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"newuserType="; nocase; content:"INSERT"; nocase; pcre:"/INSERT.+INTO/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006053; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language INSERT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php language INSERT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"language="; nocase; content:"INSERT"; nocase; pcre:"/INSERT.+INTO/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006035; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname UNION SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php lastname UNION SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"lastname="; nocase; content:"UNION"; nocase; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006004; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, m
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserType DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserType DELETE
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserType DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserType DELETE"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"newuserType="; nocase; content:"DELETE"; nocase; pcre:"/DELETE.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006054; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id UPDATE
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id UPDATE"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"id="; nocase; content:"UPDATE"; nocase; pcre:"/UPDATE.+SET/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006032; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_t
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php firstname ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php firstname ASCII
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php firstname ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php firstname ASCII"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"firstname="; nocase; content:"SELECT"; nocase; pcre:"/ASCII\(.+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006013; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_tech
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail UPDATE
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail UPDATE"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"newuserEmail="; nocase; content:"UPDATE"; nocase; pcre:"/UPDATE.+SET/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006062; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mit
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo DELETE
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php goTo DELETE"; flow:established,to_server; http.uri; content:"/search.php?"; nocase; content:"goTo="; nocase; content:"DELETE"; nocase; pcre:"/DELETE.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006066; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- save.php groupAddName UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- save.php groupAddName UNION SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- save.php groupAddName UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- save.php groupAddName UNION SELECT"; flow:established,to_server; http.uri; content:"/save.php?"; nocase; content:"groupAddName="; nocase; content:"UNION"; nocase; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006076; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initi
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php id SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"id="; nocase; content:"SELECT"; nocase; pcre:"/SELECT.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006027; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search INSERT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- search.php search INSERT"; flow:established,to_server; http.uri; content:"/search.php?"; nocase; content:"search="; nocase; content:"INSERT"; nocase; pcre:"/INSERT.+INTO/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006071; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter INSERT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php defaultLetter INSERT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"defaultLetter="; nocase; content:"INSERT"; nocase; pcre:"/INSERT.+INTO/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006041; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access,
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass UPDATE
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserPass UPDATE"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"newuserPass="; nocase; content:"UPDATE"; nocase; pcre:"/UPDATE.+SET/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006050; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php firstname SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php firstname SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php firstname SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php firstname SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"firstname="; nocase; content:"SELECT"; nocase; pcre:"/SELECT.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006009; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techn
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail INSERT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail INSERT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"newuserEmail="; nocase; content:"INSERT"; nocase; pcre:"/INSERT.+INTO/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006059; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mi
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php passwordNew UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php passwordNew UNION SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php passwordNew UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php passwordNew UNION SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; fast_pattern; content:"passwordNew="; nocase; distance:0; content:"UNION"; nocase; distance:0; pcre:"/^\s+SELECT/Ri"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006022; rev:10; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_11_02, mitre_tactic_i
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail SELECT
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php newuserEmail SELECT"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"newuserEmail="; nocase; content:"SELECT"; nocase; pcre:"/SELECT.+FROM/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006057; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mi
Suricata
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php passwordOld ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2006-4575 [HIGH] ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php passwordOld ASCII
ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php passwordOld ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS The Address Book SQL Injection Attempt -- user.php passwordOld ASCII"; flow:established,to_server; http.uri; content:"/user.php?"; nocase; content:"passwordOld="; nocase; content:"SELECT"; nocase; pcre:"/ASCII\(.+SELECT/i"; reference:cve,CVE-2006-4575; reference:url,www.securityfocus.com/bid/21870; classtype:web-application-attack; sid:2006019; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitr
No public exploits indexed.
No writeups or analysis indexed.
2020-08-27
Published