First published: Tue Feb 11 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.2 allow remote attackers to inject arbitrary web script or HTML via (1) vectors involving PHP scripts and (2) unspecified other vectors.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Web Gateway | <=5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5013 can allow remote attackers to inject arbitrary web scripts or HTML, leading to potential data theft and session hijacking.
If your version of Symantec Web Gateway is prior to 5.2, it is likely affected by CVE-2013-5013.
The recommended fix for CVE-2013-5013 is to upgrade to Symantec Web Gateway version 5.2 or later.
CVE-2013-5013 can lead to Cross-Site Scripting (XSS) attacks, allowing attackers to execute malicious scripts in the context of the user's browser.
CVE-2013-5013 may be exploited via PHP scripts and potentially other unspecified vectors in the management console.