Description
|
|
Multiple vulnerabilities have been identified in Symantec IM Manager, which could be exploited by attackers or malicious users to manipulate and inject SQL queries. These issues are caused by input validation errors in the "rdpageimlogic.aspx", "DetailReportGroup.lgx", "SummaryReportGroup.lgx", "LoggedInUSers.lgx", "IMAdminReportTrendFormRun.asp" and "IMAdminScheduleReport.asp" scripts when processing the "rdReport", "selclause", "whereTrendTimeClause", "TrendTypeForReport", "whereProtocolClause", "groupClause", "loginTimeStamp", "dbo", "dateDiffParam", "whereClause", and "groupList" parameters, which could be exploited to conduct SQL injection attacks.
|