Symantec Web Gateway CVE-2013-4670 Cross Site Scripting and HTML Injection Vulnerabilities
BID:61103
Info
Symantec Web Gateway CVE-2013-4670 Cross Site Scripting and HTML Injection Vulnerabilities
| Bugtraq ID: | 61103 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4670 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2013 12:00AM |
| Updated: | Jul 26 2013 07:24AM |
| Credit: | Stefan Viehböck of SEC Consult |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Symantec Web Gateway CVE-2013-4670 Cross Site Scripting and HTML Injection Vulnerabilities
Symantec Web Gateway is prone to a cross-site scripting vulnerability and an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Symantec Web Gateway 5.1.1 are vulnerable.
Symantec Web Gateway is prone to a cross-site scripting vulnerability and an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Symantec Web Gateway 5.1.1 are vulnerable.
Exploit / POC
Symantec Web Gateway CVE-2013-4670 Cross Site Scripting and HTML Injection Vulnerabilities
An attacker can exploit these issues using a browser. To exploit a cross-site scripting vulnerability the attacker entices an unsuspecting user to visit a specially crafted URL.
An attacker can exploit these issues using a browser. To exploit a cross-site scripting vulnerability the attacker entices an unsuspecting user to visit a specially crafted URL.
Solution / Fix
Symantec Web Gateway CVE-2013-4670 Cross Site Scripting and HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Symantec Web Gateway CVE-2013-4670 Cross Site Scripting and HTML Injection Vulnerabilities
References:
References:
- Symantec Home Page (Symantec)
- Symantec Web Gateway (Symantec)