CVE-2012-2953: OS Command Injection
Published Jul 23, 2012
·Updated
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.
Affected Software
4 affected components
Symantec Web Gateway=5.0
Symantec Web Gateway=5.0.1
Symantec Web Gateway=5.0.2
Symantec Web Gateway=5.0.3
Event History
Jul 23, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2953?
CVE-2012-2953 is classified as a high severity vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2012-2953?
To mitigate CVE-2012-2953, upgrade Symantec Web Gateway to version 5.0.3.18 or later.
3
What software versions are affected by CVE-2012-2953?
CVE-2012-2953 affects Symantec Web Gateway versions 5.0, 5.0.1, 5.0.2, and 5.0.3.
4
Can CVE-2012-2953 be exploited remotely?
Yes, CVE-2012-2953 can be exploited remotely by attackers through crafted input.
5
What is the impact of CVE-2012-2953 on affected systems?
The impact of CVE-2012-2953 includes the potential for remote execution of arbitrary commands on the affected systems.