SQL injection vulnerability in login.php in the GUI management console in Symantec Web Gateway 4.5 before 4.5.0.376 allows remote attackers to execute arbitrary SQL commands via the USERNAME parameter.
| Software | From | Fixed in |
|---|---|---|
| symantec / web_gateway | 4.5 | 4.5.x |
| symantec / web_gateway | 4.5.0.325 | 4.5.0.325.x |
| symantec / web_gateway | 4.5.0.326 | 4.5.0.326.x |
| symantec / web_gateway | 4.5.0.327 | 4.5.0.327.x |