Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.105142
Category:Web application abuses
Title:Symantec Web Gateway < 5.2.2 Command Injection Vulnerability
Summary:Symantec Web Gateway is prone to a command injection; vulnerability.
Description:Summary:
Symantec Web Gateway is prone to a command injection
vulnerability.

Vulnerability Insight:
Symantec was notified of an OS command injection vulnerability
in PHP script which impacts the SWG management console. The results of successful exploitation
could potentially range from unauthorized disclosure of sensitive data to possible unauthorized
access to the Symantec Web Gateway Appliance.

Vulnerability Impact:
Successfully exploiting this issue may allow an attacker to
execute arbitrary OS commands in the context of the affected appliance.

Affected Software/OS:
Symantec Web Gateway versions prior to 5.2.2.

Solution:
Update to version 5.2.2 or later.

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-7285
BugTraq ID: 71620
http://www.securityfocus.com/bid/71620
http://www.exploit-db.com/exploits/36263
http://karmainsecurity.com/KIS-2014-19
http://packetstormsecurity.com/files/130612/Symantec-Web-Gateway-5-restore.php-Command-Injection.html
http://osvdb.org/show/osvdb/116009
http://www.securitytracker.com/id/1031386
CopyrightCopyright (C) 2014 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.