Websense User-Agent Spoofing Filtering Security Bypass Vulnerability
BID:26847
Info
Websense User-Agent Spoofing Filtering Security Bypass Vulnerability
| Bugtraq ID: | 26847 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2007 12:00AM |
| Updated: | Dec 13 2007 09:52PM |
| Credit: | mrhinkydink discovered this vulnerability. |
| Vulnerable: |
Websense Websense Enterprise 6.3.1 |
| Not Vulnerable: | |
Discussion
Websense User-Agent Spoofing Filtering Security Bypass Vulnerability
Websense is prone to a security-bypass vulnerability because it fails to properly enforce filtering rules.
A successful attack will allow an attacker to bypass content-filtering and access forbidden websites.
This issue affects Websense Enterprise 6.3.1; other versions may also be vulnerable.
Websense is prone to a security-bypass vulnerability because it fails to properly enforce filtering rules.
A successful attack will allow an attacker to bypass content-filtering and access forbidden websites.
This issue affects Websense Enterprise 6.3.1; other versions may also be vulnerable.
Exploit / POC
Websense User-Agent Spoofing Filtering Security Bypass Vulnerability
An attacker can exploit this issue through a browser and standard tools.
An attacker can exploit this issue through a browser and standard tools.
Solution / Fix
Websense User-Agent Spoofing Filtering Security Bypass Vulnerability
Solution:
This issue has been reported to be fixed by the vendor in database #92938. Websense has also released an advisory and automatic updates to address this issue. Please see the references for more information.
Solution:
This issue has been reported to be fixed by the vendor in database #92938. Websense has also released an advisory and automatic updates to address this issue. Please see the references for more information.
References
Websense User-Agent Spoofing Filtering Security Bypass Vulnerability
References:
References:
- Websense Homepage (Websense)
- Websense Knowledgebase Reference Number: 976 (Websense)
- Websense Policy Filtering Bypass (mrhinkydink)