CVE-2012-0307: Symantec Messaging Gateway

Medium severity, CVSS 4.3. EPSS: 2% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in Symantec Messaging Gateway (SMG) before 10.0 allow remote attackers to inject arbitrary web script or HTML via (1) web content or (2) e-mail content.

Affected products

  • Symantec Messaging Gateway: up to and including 9.5.4; version 9.5 only; version 9.5.1 only; version 9.5.2 only; version 9.5.3 only

Published 2012-08-29. Last modified 2026-06-16.