Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-2961. PoCs published by muts.
AI-analyzed exploit summary This exploit leverages a blind SQL injection vulnerability in Symantec Web Gateway 5.0.3.18 to create a MySQL trigger that adds a backdoor user account. The trigger is activated upon a system reboot, allowing unauthorized access.
Description
SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Exploits (1)
This exploit leverages a blind SQL injection vulnerability in Symantec Web Gateway 5.0.3.18 to create a MySQL trigger that adds a backdoor user account. The trigger is activated upon a system reboot, allowing unauthorized access.