Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-2957. PoCs published by muts.
AI-analyzed exploit summary This exploit leverages a Local File Inclusion (LFI) vulnerability in Symantec Web Gateway 5.0.3.18 to inject a base64-encoded reverse shell payload into the access log, which is then executed via a sudo misconfiguration on /tmp/networkScript, resulting in remote root command execution.
Description
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue.
Exploits (1)
This exploit leverages a Local File Inclusion (LFI) vulnerability in Symantec Web Gateway 5.0.3.18 to inject a base64-encoded reverse shell payload into the access log, which is then executed via a sudo misconfiguration on /tmp/networkScript, resulting in remote root command execution.