Websense Enterprise Blocked Sites Cross-Site Scripting Vulnerability
BID:9149
Info
Websense Enterprise Blocked Sites Cross-Site Scripting Vulnerability
| Bugtraq ID: | 9149 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 03 2003 12:00AM |
| Updated: | Dec 03 2003 12:00AM |
| Credit: | Discovery is credited to "Mr. P.Taylor" <[email protected]>. |
| Vulnerable: |
Websense Websense Enterprise 5.1 Websense Websense Enterprise 5.0 1 Websense Websense Enterprise 4.4 Websense Websense Enterprise 4.3 |
| Not Vulnerable: | |
Discussion
Websense Enterprise Blocked Sites Cross-Site Scripting Vulnerability
Websense Enterprise displays error pages for blocked sites without sufficiently sanitizing HTML and script code from the blocked site URI. This could allow for cross-site scripting attacks if a victim user visits a link to a blocked site that includes hostile HTML and script code. Exploitation could permit theft of cookie-based authentication credentials or other consequences.
Websense Enterprise displays error pages for blocked sites without sufficiently sanitizing HTML and script code from the blocked site URI. This could allow for cross-site scripting attacks if a victim user visits a link to a blocked site that includes hostile HTML and script code. Exploitation could permit theft of cookie-based authentication credentials or other consequences.
Exploit / POC
Websense Enterprise Blocked Sites Cross-Site Scripting Vulnerability
The following example was provided:
http://[BlockedSite]?<SCRIPT>alert('hello')</SCRIPT>
The following example was provided:
http://[BlockedSite]?<SCRIPT>alert('hello')</SCRIPT>
Solution / Fix
Websense Enterprise Blocked Sites Cross-Site Scripting Vulnerability
Solution:
The vendor has produced patches for 5.01 and 5.1 on Windows/Solaris/Linux platforms. Further details on how to apply fixes are available in the attached Websense Knowledgebase Reference Number: 1061 article.
Websense Websense Enterprise 5.0 1
Websense Websense Enterprise 5.1
Solution:
The vendor has produced patches for 5.01 and 5.1 on Windows/Solaris/Linux platforms. Further details on how to apply fixes are available in the attached Websense Knowledgebase Reference Number: 1061 article.
Websense Websense Enterprise 5.0 1
-
Websense BrowserSecurityHotFix5.0.1Lin.zip
Linux platforms.
ftp://ws4:[email protected]/BrowserSecurityHotFix5.0.1Lin.zip -
Websense BrowserSecurityHotFix5.0.1Sol.zip
Solaris platforms.
ftp://ws4:[email protected]/BrowserSecurityHotFix5.0.1Sol.zip -
Websense BrowserSecurityHotFix5.0.1Win.zip
Windows platforms.
ftp://ws4:[email protected]/BrowserSecurityHotFix5.0.1Win.zip
Websense Websense Enterprise 5.1
-
Websense BrowserSecurityHotFix5.1Lin.zip
Linux platforms.
ftp://ws4:[email protected]/BrowserSecurityHotFix5.1Lin.zip -
Websense BrowserSecurityHotFix5.1Sol.zip
Solaris platforms.
ftp://ws4:[email protected]/BrowserSecurityHotFix5.1Sol.zip -
Websense BrowserSecurityHotFix5.1Win.zip
Windows platforms.
ftp://ws4:[email protected]/BrowserSecurityHotFix5.1Win.zip
References
Websense Enterprise Blocked Sites Cross-Site Scripting Vulnerability
References:
References:
- Websense Homepage (Websense)
- RE: Websense Blocked Sites XSS ("Hubbard, Dan"
) - Websense Blocked Sites XSS ("Mr. P.Taylor"
)