vendor:
Web Gateway
by:
Tenable Network Security, juan vazquez
N/A
CVSS
N/A
Arbitrary File Upload
434
CWE
Product Name: Web Gateway
Affected Version From: 5.0.2.8
Affected Version To: 5.0.2.8
Patch Exists: NO
Related CWE: CVE-2012-0299
CPE: a:symantec:web_gateway
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
Symantec Web Gateway 5.0.2.8 Arbitrary PHP File Upload Vulnerability
This module exploits a file upload vulnerability found in Symantec Web Gateway's HTTP service. Due to the incorrect use of file extensions in the upload_file() function, this allows us to abuse the spywall/blocked_file.php file in order to upload a malicious PHP file without any authentication, which results in arbitrary code execution.
Mitigation:
No mitigation available