CVE-2012-0296: XSS
Published May 21, 2012
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
3 affected components
Symantec Web Gateway=5.0
Symantec Web Gateway=5.0.1
Symantec Web Gateway=5.0.2
Event History
May 21, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0296?
CVE-2012-0296 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2012-0296?
To fix CVE-2012-0296, upgrade Symantec Web Gateway to version 5.0.3 or later.
3
What types of attacks are possible with CVE-2012-0296?
CVE-2012-0296 allows remote attackers to inject arbitrary web scripts or HTML into the management GUI.
4
Which versions of Symantec Web Gateway are affected by CVE-2012-0296?
Symantec Web Gateway versions 5.0, 5.0.1, and 5.0.2 are affected by CVE-2012-0296.
5
Where can I find more information about CVE-2012-0296?
Information regarding CVE-2012-0296 can typically be found in security advisories from Symantec or security databases.