First published: Wed Aug 29 2012(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Symantec Messaging Gateway (SMG) before 10.0 allow remote attackers to inject arbitrary web script or HTML via (1) web content or (2) e-mail content.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Symantec Messaging Gateway | <=9.5.4 | |
Broadcom Symantec Messaging Gateway | =9.5 | |
Broadcom Symantec Messaging Gateway | =9.5.1 | |
Broadcom Symantec Messaging Gateway | =9.5.2 | |
Broadcom Symantec Messaging Gateway | =9.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0307 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To remediate CVE-2012-0307, users should upgrade to Symantec Messaging Gateway version 10.0 or later.
CVE-2012-0307 allows attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
CVE-2012-0307 affects Symantec Messaging Gateway versions prior to 10.0, including all versions up to and including 9.5.4.
Yes, CVE-2012-0307 can be exploited through email content, allowing remote attackers to inject scripts.