Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-0308. PoCs published by Ben Williams.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Symantec Messaging Gateway 9.5.3-3, allowing an attacker to add a backdoor administrator account via a crafted image tag. The lack of CSRF protection and password validation on sensitive functions enables this attack.
Description
Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to hijack the authentication of administrators.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in Symantec Messaging Gateway 9.5.3-3, allowing an attacker to add a backdoor administrator account via a crafted image tag. The lack of CSRF protection and password validation on sensitive functions enables this attack.