alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SPECIFIC SFS EZ BIZ PRO track.php id Parameter Remote SQL Injection"; flow:established,to_server; content:"GET "; depth:4; uricontent:"/track.php?"; nocase; uricontent:"id="; nocase; uricontent:"UNION"; nocase; uricontent:"SELECT"; nocase; distance:0; classtype:web-application-attack; reference:url,secunia.com/advisories/32552/; reference:url,milw0rm.com/exploits/6910; sid:2008793; rev:1;)
Added 2008-11-18 09:30:22 UTC