CVE-2012-0297

Scores

EPSS

0.895high89.5%
0%20%40%60%80%100%

Percentile: 89.5%

CVSS

10.0critical2.0
0246810

CVSS Score: 10.0/10

All CVSS Scores

CVSS 2.0
10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Description

The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-264

Exploits

Exploit ID: 18932

Source: exploitdb

URL: https://www.exploit-db.com/exploits/18932

Exploit ID: 18942

Source: exploitdb

URL: https://www.exploit-db.com/exploits/18942

Exploit ID: 19065

Source: exploitdb

URL: https://www.exploit-db.com/exploits/19065

Exploit ID: 19406

Source: exploitdb

URL: https://www.exploit-db.com/exploits/19406

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: web_gateway

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:symantec:web_gateway:5.0:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:symantec:web_gateway:5.0.1:*:*:*:*:*:*...

Source: nvd

End of list