CVE-2013-4672 Information
Feb 14, 2021
cve
Description
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 has an incorrect sudoers file which allows local users to bypass intended access restrictions via a command.
Reference
http://osvdb.org/95695 http://packetstormsecurity.com/files/122556/Symantec-Web-Gateway-XSS-CSRF-SQL-Injection-Command-Injection.html http://www.securityfocus.com/bid/61104 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130725_00 https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20130726-0_Symantec_Web_Gateway_Multiple_Vulnerabilities_v10.txt
Share on: