Skip to main content

Vendor/product archive

symantec / web_gateway CVEs

Beta · best-effort

35 CVEs tagged to symantec / web_gateway5 Critical, 14 High, 15 Medium, 1 Low, 0 Unrated.

CVE-2016-5313

Published Apr 12, 2017

Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6548

Published Sep 20, 2015

Multiple SQL injection vulnerabilities in a PHP script in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote aut…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6547

Published Sep 20, 2015

The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands at boot ti…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5693

Published Sep 20, 2015

The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands via vector…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5692

Published Sep 20, 2015

admin_messages.php in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitra…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5691

Published Sep 20, 2015

Multiple cross-site scripting (XSS) vulnerabilities in PHP scripts in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5690

Published Sep 20, 2015

The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass intended access restrictions a…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-7285

Published Dec 17, 2014

The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings int…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1652

Published Jun 18, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec Web Gateway (SWG) before 5.2 allow remote authenticated users to inject arbitrary web scr…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-1651

Published Jun 18, 2014

SQL injection vulnerability in clientreport.php in the management console in Symantec Web Gateway (SWG) before 5.2 allows remote attackers to execute arbitrary SQL commands via un…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1650

Published Jun 18, 2014

SQL injection vulnerability in user.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote authenticated users to execute arbitrary SQL commands vi…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5017

Published Jun 18, 2014

SNMPConfig.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote attackers to execute arbitrary commands via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-5013

Published Feb 11, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.2 allow remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5012

Published Feb 11, 2014

Multiple SQL injection vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.2 allow remote authenticated users to execute arbitrary SQL c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4178

Published Aug 7, 2012

SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid par…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2977

Published Jul 23, 2012

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2976

Published Jul 23, 2012

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to application scripts, related…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 35 CVEsPage 1 of 2