Vulnerability CVE-2012-0297


Published: 2012-05-21   Modified: 2012-05-22

Description:
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data.

See advisories in our WLB2 database:
Topic
Author
Date
High
Symantec Web Gateway Shell Command Injection Remote Code Execution
ZDI
09.06.2012
High
Symantec Web Gateway 5.0.2.8 Multiple Vulnerabilities
S2 Crew
28.06.2012

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Symantec -> Web gateway 

 References:
http://www.securityfocus.com/bid/53444
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120517_00
https://exchange.xforce.ibmcloud.com/vulnerabilities/75731

Copyright 2024, cxsecurity.com

 

Back to Top