Sploitus

CVE-2012-4347

4 known exploits for CVE-2012-4347

Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) logFile parameter in a logs action to brightmail/export or (2) localBackupFileSelection parameter in an APPLIANCE restoreSource action to brightmail/admin/restore/download.do.

Symantec Messaging Gateway
= 9.5, 9.5.1, 9.5.2, 9.5.3, 9.5.4
Fix
Available
CVSS 2.0
5.0 MEDIUM
EPSS
58.8% (99th percentile)
Weakness
CWE-22
NVD status
Modified
Published
2012-12-05
CVE-2012-4347 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2012-4347

Proof-of-concept code and exploit modules indexed by Sploitus