CVE-2012-0297

EXPLOITED

Symantec Web Gateway <5.0.3 - RCE

Title source: llm

Description

The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data.

Exploits (6)

metasploit WORKING POC EXCELLENT
by Unknown, muts, sinn3r · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/symantec_web_gateway_lfi.rb
exploitdb WORKING POC VERIFIED
by muts · pythonwebappslinux
https://www.exploit-db.com/exploits/18932
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/18942
exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/19065
exploitdb WORKING POC
webappslinux
https://www.exploit-db.com/exploits/19406
metasploit WORKING POC EXCELLENT
by Unknown, juan vazquez · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/symantec_web_gateway_exec.rb

Scores

EPSS 0.8946
EPSS Percentile 99.5%

Exploitation Intel

VulnCheck KEV 2023-12-06

Classification

CWE
CWE-264
Status draft

Affected Products (3)

symantec/web_gateway
symantec/web_gateway
symantec/web_gateway

Timeline

Published May 21, 2012
Tracked Since Feb 18, 2026