header-logo
Suggest Exploit
vendor:
Web Gateway
by:
Unknown, muts, sinn3r
N/A
CVSS
N/A
Command Execution
CWE
Product Name: Web Gateway
Affected Version From:
Affected Version To:
Patch Exists:
Related CWE: CVE-2012-0297
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
Unknown

Symantec Web Gateway 5.0.2.8 Command Execution Vulnerability

This module exploits a vulnerability found in Symantec Web Gateway's HTTP service. By injecting PHP code in the access log, it is possible to load it with a directory traversal flaw, which allows remote code execution under the context of 'apache'. Please note that it may take up to several minutes to retrieve access_log, which is about the amount of time required to see a shell back.

Mitigation:

Source

Exploit-DB raw data: