Skip to main content

Symantec Web Gateway `l´ Cross-Site Scripting Vulnerability

Last Update Date: 7 Jun 2013 Release Date: 8 May 2012 5151 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in Symantec Web Gateway, which can be exploited by malicious people to conduct cross-site scripting attacks.

 

Input passed via the "l" parameter to spywall/timer.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.


Impact

  • Cross-Site Scripting
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • version 5.0.2.8.
  • Other versions may also be affected.

Solutions

  • Filter malicious characters and character sequences using a proxy.

Vulnerability Identifier

  • No CVE information is available

Source

 


Related Link