Описание
fw_charts.php in the reporting module in the Manager (aka SEPM) component in Symantec Endpoint Protection (SEP) 11.x before 11 RU6 MP2 allows remote attackers to bypass intended restrictions on report generation, overwrite arbitrary PHP scripts, and execute arbitrary code via a crafted request.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:symantec:endpoint_protection:11.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0:ru5:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0:ru6:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0:ru6mp1:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0.1:*:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0.1:mp1:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0.2:*:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0.2:mp1:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0.2:mp2:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0.4:*:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0.4:mp1a:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0.4:mp2:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0.3001:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.0276
Низкий
7.5 High
CVSS2
Дефекты
CWE-20
Связанные уязвимости
github
почти 4 года назад
fw_charts.php in the reporting module in the Manager (aka SEPM) component in Symantec Endpoint Protection (SEP) 11.x before 11 RU6 MP2 allows remote attackers to bypass intended restrictions on report generation, overwrite arbitrary PHP scripts, and execute arbitrary code via a crafted request.
EPSS
Процентиль: 86%
0.0276
Низкий
7.5 High
CVSS2
Дефекты
CWE-20