vendor:
Symantec Messaging Gateway
by:
Ben Williams
6,5
CVSS
MEDIUM
Arbitrary file download
N/A
CWE
Product Name: Symantec Messaging Gateway
Affected Version From: 9.5.3-3
Affected Version To: 9.5.3-3
Patch Exists: YES
Related CWE: N/A
CPE: a:symantec:symantec_messaging_gateway
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Symantec Messaging Gateway – Arbitrary file download is possible with a crafted URL (authenticated)
The vulnerability would enable an attacker (who has authenticated to the web interface) to download arbitrary files from the appliance with the permissions of the Webserver user. Various files containing sensitive information can be downloaded using a crafted URL for example: http://192.168.1.59:41080/brightmail/export?type=logs&logFile=../../../etc/passwd&logType=1&browserType=1.
Mitigation:
Upgrade to the latest version of Symantec Messaging Gateway