← back
CVE-2012-0297observed exploitation

CVE-2012-0297

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 73%
from disclosure to weapon5 days
Published on NVDMay 21
1st PoC+5d
metasploitMay 17
VulnCheck+4216d
exploitation probability
73%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.