← All CVEs

CVE-2014-7285

medium · 6.5

The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.

6.5
CVSS
50.3%
EPSS (exploit prob.)
99th
EPSS percentile
2014-12-17
Published

AV:N/AC:L/Au:S/C:P/I:P/A:P

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
symantecweb_gateway<= 5.2.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-7285