Symantec Web Security Block Page Message Cross-Site Scripting Vulnerability
BID:9418
Info
Symantec Web Security Block Page Message Cross-Site Scripting Vulnerability
| Bugtraq ID: | 9418 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2004 12:00AM |
| Updated: | Jan 14 2004 12:00AM |
| Credit: | The disclosure of this issue has been credited to Oliver Karow and Brian Soby of Raytheon. |
| Vulnerable: |
Symantec Web Security 3.0.1 Symantec Web Security 3.0 Symantec Web Security 2.5 |
| Not Vulnerable: |
Symantec Web Security 3.0.1 Build 62 |
Discussion
Symantec Web Security Block Page Message Cross-Site Scripting Vulnerability
It has been reported that Symantec Web Security is prone to a cross-site scripting vulnerability that may allow an attacker to steal cookie-based authentication credentials due to improper sanitization of user-supplied data. HTML and script code may be parsed via URI parameters included in an error or block page message.
Symantec Web Security versions 2.5, 3.0.0, and 3.0.1 have been reported to be vulnerable to this issue.
It has been reported that Symantec Web Security is prone to a cross-site scripting vulnerability that may allow an attacker to steal cookie-based authentication credentials due to improper sanitization of user-supplied data. HTML and script code may be parsed via URI parameters included in an error or block page message.
Symantec Web Security versions 2.5, 3.0.0, and 3.0.1 have been reported to be vulnerable to this issue.
Exploit / POC
Symantec Web Security Block Page Message Cross-Site Scripting Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Symantec Web Security Block Page Message Cross-Site Scripting Vulnerability
Solution:
Symantec has reported that this issue has been addressed in Symantec Web Security version 3.0.1 build 62. Users are advised to contact the vendor to obtain the fixed version.
Solution:
Symantec has reported that this issue has been addressed in Symantec Web Security version 3.0.1 build 62. Users are advised to contact the vendor to obtain the fixed version.
References
Symantec Web Security Block Page Message Cross-Site Scripting Vulnerability
References:
References: