Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7288
Reference (s):
- BID:72308
- URL: http://www.securityfocus.com/bid/72308
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20150129_00
- EXPLOIT-DB:35949
- URL: http://www.exploit-db.com/exploits/35949

