vendor:
Web Gateway
by:
muts, sinn3r
N/A
CVSS
N/A
Command Injection
78
CWE
Product Name: Web Gateway
Affected Version From: 5.0.2.18
Affected Version To: 5.0.2.18
Patch Exists: NO
Related CWE: CVE-2012-2953
CPE: a:symantec:web_gateway:5.0.2.18
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix
2012
Symantec Web Gateway 5.0.2.18 pbcontrol.php Command Injection
This module exploits a command injection vulnerability found in Symantec Web Gateway's HTTP service. While handling the filename parameter, the Spywall API does not do any filtering before passing it to an exec() call in proxy_file(), thus results in remote code execution under the context of the web server. Please note authentication is NOT needed to gain access.
Mitigation:
No mitigation or remediation available