Vulnerabilities > Symantec > WEB Gateway > Medium

DATE CVE VULNERABILITY TITLE RISK
2013-08-01 CVE-2013-4671 Cross-Site Request Forgery (CSRF) vulnerability in Symantec products
Cross-site request forgery (CSRF) vulnerability in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
network
symantec CWE-352
6.0
2013-08-01 CVE-2013-4670 Cross-Site Scripting vulnerability in Symantec products
Multiple cross-site scripting (XSS) vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
symantec CWE-79
4.3
2012-07-23 CVE-2012-2977 Permissions, Privileges, and Access Controls vulnerability in Symantec web Gateway
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script.
network
low complexity
symantec CWE-264
5.0
2012-05-21 CVE-2012-0298 Permissions, Privileges, and Access Controls vulnerability in Symantec web Gateway 5.0/5.0.1/5.0.2
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitrary files via unspecified vectors.
network
low complexity
symantec CWE-264
6.4
2012-05-21 CVE-2012-0296 Cross-Site Scripting vulnerability in Symantec web Gateway 5.0/5.0.1/5.0.2
Multiple cross-site scripting (XSS) vulnerabilities in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
symantec CWE-79
4.3