Symantec Web Gateway CVE-2014-1652 Multiple Cross Site Scripting Vulnerabilities
BID:67755
Info
Symantec Web Gateway CVE-2014-1652 Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 67755 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1652 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2014 12:00AM |
| Updated: | Jun 18 2014 12:04AM |
| Credit: | Min1214 of INFOSEC Inc |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Symantec Web Gateway CVE-2014-1652 Multiple Cross Site Scripting Vulnerabilities
Symantec Web Gateway is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Symantec Web Gateway versions prior to 5.2.1 are vulnerable.
Symantec Web Gateway is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Symantec Web Gateway versions prior to 5.2.1 are vulnerable.
Exploit / POC
Symantec Web Gateway CVE-2014-1652 Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Symantec Web Gateway CVE-2014-1652 Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Symantec Web Gateway CVE-2014-1652 Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Symantec Web Gateway (Symantec)