Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2012-2953

Severity
10.0CRITICAL
EPSS
83.4%
top 0.72%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 23
Latest updateMay 17

Description

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDsymantec/web_gateway4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-vxg9-3cxj-rj2h: The management console in Symantec Web Gateway 52022-05-17
CVEList
CVE-2012-2953: The management console in Symantec Web Gateway 52012-07-23

💥Exploits & PoCs

2
Exploit-DB
Symantec Web Gateway 5.0.2.18 - 'pbcontrol.php' Command Injection (Metasploit)2012-07-27
Exploit-DB
Symantec Web Gateway 5.0.3.18 - 'pbcontrol.php' Root Remote Code Execution2012-07-24

💬Community

1
Bugzilla
CVE-2012-4670 tigase: Prone to unsolicited XMPP Dialback attacks2012-08-27