CVE-2012-0297
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 73%
from disclosure to weapon5 days
Published on NVDMay 21
1st PoC+5d
metasploitMay 17
VulnCheck+4216d
exploitation probability
73%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data.
Affected products
n/a · n/apublic PoCs found — 4
exploitdbwww.exploit-db.com/exploits/18942unverifiedexploitdbwww.exploit-db.com/exploits/18932unverifiedexploitdbwww.exploit-db.com/exploits/19406unverifiedexploitdbwww.exploit-db.com/exploits/19065unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.