Record summary

CVE-2016-10258 has a selected CVSS score of 6.8 (medium); EIP currently links 1 catalogued exploit.

Description

Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List6.6 prior to 6.6.5.14affected
6.7 prior to 6.7.3.1affected
CVE List6.5 prior to 6.5.10.8affected
6.6 prior to 6.6.5.14affected
6.7 prior to 6.7.3.1affected

Proofs of concept

1

Catalogued exploits

ExploitDBSymantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File UploadExploitDB exploitby Pankaj Kumar ThakurNot analyzed1 file
ExploitDB

PoC details

References

4