This allows remote attackers to bypass intended restrictions on report generation, overwrite arbitrary PHP scripts, and execute arbitrary code via a crafted request.
Symantec Endpoint Protection (SEP) reporting module is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary PHP code on the server that the SEP client connects to.
Vendor Status:
Symantec as issued an update for this vulnerablity