Exploitation Summary
EIP tracks 2 public exploits for CVE-2012-2977. PoCs published by Kc57.
AI-analyzed exploit summary This Metasploit auxiliary module exploits CVE-2012-2977 to arbitrarily change the password of any user on Symantec Web Gateway <= 5.0.3.18 by leveraging an unauthenticated password reset vulnerability in the `/spywall/temppassword.php` endpoint.
Description
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script.
Exploits (2)
This Metasploit auxiliary module exploits CVE-2012-2977 to arbitrarily change the password of any user on Symantec Web Gateway <= 5.0.3.18 by leveraging an unauthenticated password reset vulnerability in the `/spywall/temppassword.php` endpoint.
This exploit targets Symantec Web Gateway <= 5.0.3.18 by sending a crafted POST request to 'temppassword.php' to arbitrarily change a user's password. It leverages a vulnerability in the password reset mechanism without requiring prior authentication.