CVE-2012-2957

HIGH

Description

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue.

References

http://www.kb.cert.org/vuls/id/108471

http://www.securityfocus.com/bid/54429

http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120720_00

https://exchange.xforce.ibmcloud.com/vulnerabilities/77113

Details

Source: MITRE

Published: 2012-07-23

Updated: 2017-12-22

Type: CWE-264

Risk Information

CVSS v2.0

Base Score: 7.2

Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C)

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH