Multiple cross-site scripting (XSS) vulnerabilities in Websense TRITON AP-WEB before...
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Websense TRITON AP-WEB before 8.0.0 and V-Series 7.7 appliances allow remote attackers to inject arbitrary web script or HTML via the (1) ws-userip in the ws-encdata parameter to cve-bin/moreBlockInfo.cgi in the Data Security block page or (2) admin_msg parameter to configure/ssl_ui/eva-config/client-cert-import_wsoem.html in the Content Gateway, which is not properly handled in an error message.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-2703
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.securify.nl/advisory/SFY20140910/cross_site_scripting_vulnerability_in_websense_data_security_block_page.html
- http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0
- http://seclists.org/fulldisclosure/2015/Mar/106
- http://seclists.org/fulldisclosure/2015/Mar/108
- http://www.securityfocus.com/archive/1/534914/100/0/threaded
- https://www.securify.nl/advisory/SFY20140916/error_messages_of_websense_content_gateway_are_vulnerable_to_cross_site_scripting.html
- http://packetstormsecurity.com/files/130902/Websense-Data-Security-Cross-Site-Scripting.html
- http://www.securityfocus.com/archive/1/534912/100/0/threaded
- http://packetstormsecurity.com/files/130908/Websense-Content-Gateway-Error-Message-Cross-Site-Scripting.html
More from websense
View All →Affected Vendor
websense
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.