7.2
CVSSv2

CVE-2012-4348

Published: 18/12/2012 Updated: 14/03/2013
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 4.1
VMScore: 641
Vector: AV:A/AC:L/Au:M/C:C/I:C/A:C

Vulnerability Summary

The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business Edition 12.x prior to 12.1 RU2, does not properly validate input for PHP scripts, which allows remote authenticated users to execute arbitrary code via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec endpoint protection 11.0.6200

symantec endpoint protection 11.0.6200.754

symantec endpoint protection 11.0.4

symantec endpoint protection 11.0.3001

symantec endpoint protection 11.0.2

symantec endpoint protection 11.0.7100

symantec endpoint protection 11.0.6000

symantec endpoint protection 11.0.6100

symantec endpoint protection 11.0

symantec endpoint protection 11.0.1

symantec endpoint protection 11.0.7000

symantec endpoint protection 11.0.6300

symantec endpoint protection 12.1

symantec endpoint protection 12.1.1000

symantec endpoint protection 12.1.671

symantec endpoint protection 12.0