The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2012-05-21T20:00:00

Updated: 2017-12-04T19:57:01

Reserved: 2012-01-04T00:00:00


Link: CVE-2012-0297

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2012-05-21T20:55:17.727

Modified: 2017-12-05T02:29:02.327


Link: CVE-2012-0297

JSON object: View

cve-icon Redhat Information

No data.

CWE