Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.symantec.com/security-center/network-protection-security-advisories/SA162 | vendor advisory |
http://www.securityfocus.com/bid/103685 | third party advisory vdb entry |
http://www.securitytracker.com/id/1040757 | third party advisory vdb entry |