CVE

Id
57591  
CVE No.
CVE-2012-4348  
Status
Candidate  
Description
The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business Edition 12.x before 12.1 RU2, does not properly validate input for PHP scripts, which allows remote authenticated users to execute arbitrary code via unspecified vectors.  
Phase
Assigned (20120816)  
Votes
None (candidate not yet proposed)  
Comments