----------------------------------------------------------------------------------------------------- Title: NETASQ Firewall - UTM suffer from bypassing metacharacters filter Date : 2012-07-27 coolkaveh Advisory coolkaveh@rocketmail.com Https://twitter.com/coolkaveh Product : Netasq utm Vendor Homepage: http://netasq.com Criticality level : High Description : A vulnerability has been discovered in Netasq UTM, which can be exploited by malicious people to bypass metacharacters filter provided by Netasq UTM. Input passed via the method POST is not properly filtering before being passes to the webserver. This can be exploited to SQL injection and etc. Credit : coolkaveh