CVE-2014-7285

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
17/12/2014
Last modified:
12/04/2025

Description

The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:symantec:web_gateway:*:*:*:*:*:*:*:* 5.2.1 (including)