CVE-2014-7285

Symantec Web Gateway <5.2.2 - Command Injection

Title source: llm

Description

The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/36263
metasploit WORKING POC EXCELLENT
by Egidio Romano, sinn3r · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/symantec_web_gateway_restore.rb

Scores

EPSS 0.7402
EPSS Percentile 98.8%

Details

CWE
CWE-77
Status published
Products (1)
symantec/web_gateway < 5.2.1
Published Dec 17, 2014
Tracked Since Feb 18, 2026