CVE-2014-9711
Summary
| CVE | CVE-2014-9711 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-03-25 14:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in the Investigative Reports in Websense TRITON AP-WEB before 8.0.0 and Web Security and Filter, Web Security Gateway, and Web Security Gateway Anywhere 7.8.3 before Hotfix 02 and 7.8.4 before Hotfix 01 allow remote attackers to inject arbitrary web script or HTML via the (1) ReportName (Job Name) parameter to the Explorer report scheduler (cgi-bin/WsCgiExplorerSchedule.exe) in the Job Queue or the col parameter to the (2) Names or (3) Anonymous (explorer_wse/explorer_anon.exe) summary report page. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Websense | Triton Ap Web | All | All | All | All |
| Application | Websense | Triton Web Filter | All | All | All | All |
| Application | Websense | Triton Web Security | All | All | All | All |
| Application | Websense | Triton Web Security Gateway | All | All | All | All |
| Application | Websense | Triton Web Security Gateway Anywhere | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: Cross-Site Scripting vulnerability in Websense Explorer report scheduler | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| v7.8.4: About Hotfix 01 for Web Security Solutions | af854a3a-2127-422b-91ae-364da2661108 | www.websense.com | Vendor Advisory |
| Full Disclosure: Multiple Cross-Site Scripting vulnerabilities in Websense Reporting | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Securify - security advisories - Cross-Site Scripting vulnerability in Websense Explorer report scheduler | af854a3a-2127-422b-91ae-364da2661108 | www.securify.nl | Exploit |
| File Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.websense.com | Vendor Advisory |
| Websense Reporting Cross Site Scripting ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Websense Explorer Report Scheduler Cross Site Scripting ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit |
| Securify | af854a3a-2127-422b-91ae-364da2661108 | www.securify.nl | Exploit |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Vulnerabilities resolved in TRITON APX Version 8.0 | af854a3a-2127-422b-91ae-364da2661108 | www.websense.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.