103685vdb entry
http://www.securityfocus.com/bid/103685 CVE-2016-10258
MEDIUM
Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File Upload
Record summary
CVE-2016-10258 has a selected CVSS score of 6.8 (medium); EIP currently links 1 catalogued exploit.
Description
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Advanced Secure Gateway (ASG)Browse Symantec Corporation / Advanced Secure Gateway (ASG) | CVE List | 6.6 prior to 6.6.5.14 | affected |
| 6.7 prior to 6.7.3.1 | affected | ||
| CVE List | 6.5 prior to 6.5.10.8 | affected | |
| 6.6 prior to 6.6.5.14 | affected | ||
| 6.7 prior to 6.7.3.1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSymantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File UploadExploitDB exploitby Pankaj Kumar ThakurNot analyzed1 file
References
41040757vdb entry
http://www.securitytracker.com/id/1040757 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-10258 symantec.comConfirmation
https://www.symantec.com/security-center/network-protection-security-advisories/SA162