Vulnerabilities > Symantec > WEB Gateway
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2013-08-01 | CVE-2013-1617 | SQL Injection vulnerability in Symantec products Multiple SQL injection vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allow remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors. | 7.4 |
2013-08-01 | CVE-2013-1616 | OS Command Injection vulnerability in Symantec products The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbitrary commands by injecting a command into an application script. | 8.3 |
2012-08-07 | CVE-2012-4178 | SQL Injection vulnerability in Symantec web Gateway 5.0.3.18 SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid parameter. | 7.5 |
2012-07-23 | CVE-2012-2977 | Permissions, Privileges, and Access Controls vulnerability in Symantec web Gateway The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script. | 5.0 |
2012-07-23 | CVE-2012-2976 | OS Command Injection vulnerability in Symantec web Gateway The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to application scripts, related to an "injection" issue. | 10.0 |
2012-07-23 | CVE-2012-2961 | SQL Injection vulnerability in Symantec web Gateway SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 7.5 |
2012-07-23 | CVE-2012-2957 | Permissions, Privileges, and Access Controls vulnerability in Symantec web Gateway The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue. | 7.2 |
2012-07-23 | CVE-2012-2953 | OS Command Injection vulnerability in Symantec web Gateway The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts. | 10.0 |
2012-07-23 | CVE-2012-2574 | SQL Injection vulnerability in Symantec web Gateway SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to a "blind SQL injection" issue. | 7.5 |
2012-05-21 | CVE-2012-0299 | Permissions, Privileges, and Access Controls vulnerability in Symantec web Gateway 5.0/5.0.1/5.0.2 The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a designated pathname, and possibly execute this code, via unspecified vectors. | 10.0 |