CVE-2015-5692

Published Sep 20, 2015

Last updated 8 years ago

Overview

Description
admin_messages.php in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary code by uploading a file with a safe extension and content type, and then leveraging an improper Sudo configuration to make this a setuid-root file.
Source
secure@symantec.com
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
7.9
Impact score
10
Exploitability score
5.5
Vector string
AV:N/AC:M/Au:M/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-264

Configurations