alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SPECIFIC
ActiveNews? Manager SQL Injection Attempt -- activeNews_comments.asp articleID INSERT"; flow:established,to_server; uricontent:"/activeNews_comments.asp?"; nocase; uricontent:"articleID="; nocase; uricontent:"INSERT"; nocase; pcre:"/.+INSERT.+INTO/Ui"; classtype:web-application-attack; reference:cve,CVE-2006-6094; reference:url,www.securityfocus.com/bid/21167; sid:2007495; rev:2;)
Added 2008-02-01 10:45:55 UTC
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"BLEEDING-EDGE WEB
ActiveNews? Manager SQL Injection Attempt -- activeNews_comments.asp articleID INSERT"; flow:established,to_server; uricontent:"/activeNews_comments.asp?"; nocase; uricontent:"articleID="; nocase; uricontent:"INSERT"; nocase; pcre:"/.+INSERT.+INTO/Ui"; classtype:web-application-attack; reference:cve,CVE-2006-6094; reference:url,www.securityfocus.com/bid/21167; sid:2007495; rev:1;)
Added 2007-08-15 03:31:57 UTC