PoC Index

CVE-2014-7285

MEDIUM 6.5EPSS 50.3%

The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.

CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
50.32% chance of exploitation in the next 30 days, 99th percentile
Published
2014-12-17
Updated
2024-08-06

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related