Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
admin_messages.php in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary code by uploading a file with a safe extension and content type, and then leveraging an improper Sudo configuration to make this a setuid-root file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Symantec Web Gateway 代码注入漏洞
Vulnerability Description
Symantec Web Gateway(SWG)是美国赛门铁克(Symantec)公司的一套网络内容过滤软件。该软件提供网络内容过滤、数据泄露防护等功能。 使用5.2.2 DB 5.0.0.1277之前版本软件的SWG设备中的管理控制台中的admin_messages.php脚本存在安全漏洞。远程攻击者可通过上传带有安全的扩展名和内容类型的文件,并使用不正确的Sudo配置将其更改为setuid-root文件利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A