Symantec Web Gateway contains a flaw related to the spywall/pbcontrol.php failing to properly sanitize input passed via the 'filename' parameter. This may allow a remote attacker to execute arbitrary shell commands.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Patch / RCS
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Third-party Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Symantec has released update 5.0.0.438 to address this vulnerability. Check the vendor advisory or solution in the references section.