PT-2014-7882 · Symantec · Symantec Web Gateway

Published

2014-12-17

·

Updated

2017-01-03

·

CVE-2014-7285

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Symantec Web Gateway versions prior to 5.2.2
Description The issue allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts in the management console of the Symantec Web Gateway appliance.
Recommendations For versions prior to 5.2.2, update to version 5.2.2 or later to resolve the issue.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7285

Affected Products

Symantec Web Gateway