alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SPECIFIC SFS EZ Hotscripts-like Site software-description.php id Parameter SQL Injection"; flow:to_server,established; content:"GET "; depth:4; uricontent:"/software-description.php?"; nocase; uricontent:"id="; nocase; uricontent:"UNION"; nocase; uricontent:"SELECT"; nocase; pcre:"/UNION.+SELECT/Ui"; classtype:web-application-attack; reference:url,secunia.com/advisories/32536/; reference:url,milw0rm.com/exploits/6915; sid:2008816; rev:1;)
Added 2008-12-02 10:00:23 UTC
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SPECIFIC SFS EZ Hotscripts-like Site software-description.php id Parameter SQL Injection"; flow:to_server,established; content:"GET "; depth:4; uricontent:"/software-description.php?"; nocase; uricontent:"id="; nocase; uricontent:"UNION"; nocase; uricontent:"SELECT"; nocase; pcre:"/UNION.+SELECT/Ui"; classtype:web-application-attack; reference:url,secunia.com/advisories/32536/; reference:url,milw0rm.com/exploits/6915; sid:2008816; rev:1;)
Added 2008-12-02 09:58:24 UTC
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SPECIFIC SFS EZ Hotscripts-like Site software-description.php id Parameter SQL Injection"; flow:to_server,established; content:"GET "; depth:4; uricontent:"/software-description.php?"; nocase; uricontent:"id="; nocase; uricontent:"UNION"; nocase; uricontent:"SELECT"; nocase; pcre:"/UNION.+SELECT/Ui"; classtype:web-application-attack; reference:url,secunia.com/advisories/32536/; reference:url,milw0rm.com/exploits/6915; sid:2008816; rev:1;)
Added 2008-12-02 09:57:12 UTC