CVE-2013-4671 – Symantec Web Gateway XSS / CSRF / SQL Injection / Command Injection
https://notcve.org/view.php?id=CVE-2013-4671
Cross-site request forgery (CSRF) vulnerability in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. Vulnerabilidad de CSRF en consola de gestión de Symantec Web Gateway (SWG) , permite a usuarios autenticados remotamente secuestrar la autenticación de víctimas sin especificar a través de vectores desconocidos. Symantec Web Gateway versions 5.1.0.* and below suffer from cross site request forgery, cross site scripting, command injection, and remote SQL injection vulnerabilities. • http://osvdb.org/95699 http://packetstormsecurity.com/files/122556/Symantec-Web-Gateway-XSS-CSRF-SQL-Injection-Command-Injection.html http://www.securityfocus.com/bid/61102 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130725_00 https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20130726-0_Symantec_Web_Gateway_Multiple_Vulnerabilities_v10.txt • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2013-4670 – Symantec Web Gateway XSS / CSRF / SQL Injection / Command Injection
https://notcve.org/view.php?id=CVE-2013-4670
Multiple cross-site scripting (XSS) vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de XSS en la consola de gestión de Symantec Web Gateway (SWG), permite a atacantes remotos inyectar secuencias de comandos web o HTML sin especificar a través de vectores sin especificar. Symantec Web Gateway versions 5.1.0.* and below suffer from cross site request forgery, cross site scripting, command injection, and remote SQL injection vulnerabilities. • http://osvdb.org/95690 http://osvdb.org/95692 http://packetstormsecurity.com/files/122556/Symantec-Web-Gateway-XSS-CSRF-SQL-Injection-Command-Injection.html http://www.securityfocus.com/bid/61103 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130725_00 https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20130726-0_Symantec_Web_Gateway_Multiple_Vulnerabilities_v10.txt • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-1614
https://notcve.org/view.php?id=CVE-2013-1614
Multiple cross-site scripting (XSS) vulnerabilities in the management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados en la consola de gestión de Java (tambíen conocida como Java console) en el componente Symantec Security Information Manager (SSIM) v4.7.x y v4.8.x anteriores a v4.8.1 permite a atacantes remotos ejecutar comandos web o HTML mediante vectores no especificados. • http://www.securityfocus.com/bid/60797 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130701_00 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-1615
https://notcve.org/view.php?id=CVE-2013-1615
The management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote attackers to obtain sensitive information via unspecified web-GUI API calls. La consola de gestión de Java (tambíen conocida como Java console) en el componente Symantec Security Information Manager (SSIM) v4.7.x y v4.8.x anteriores a v4.8.1 permite a atacantes remotos a obtener información sensible a través de llamadas a la API web-GUI no especificadas. • http://www.securityfocus.com/bid/60798 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130701_00 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2013-1613
https://notcve.org/view.php?id=CVE-2013-1613
SQL injection vulnerability in the management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en la consola de gestión de Java (tambíen conocida como Java console) en el componente Symantec Security Information Manager (SSIM) v4.7.x y v4.8.x anteriores a v4.8.1 permite a atacantes remotos ejecutar comandos SQL a través de vectores no especificados. • http://www.securityfocus.com/bid/60796 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130701_00 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •