|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[SA10990] Symantec Gateway Security Cross Site Scripting Vulnerability
From: Secunia Security Advisories (sec-adv
secunia.com)
Date: Fri Feb 27 2004 - 04:00:07 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
TITLE:
Symantec Gateway Security Cross Site Scripting Vulnerability
SECUNIA ADVISORY ID:
SA10990
VERIFY ADVISORY:
http://secunia.com/advisories/10990/
CRITICAL:
Less critical
IMPACT:
Cross Site Scripting
WHERE:
From remote
SOFTWARE:
Symantec Gateway Security 2.x
DESCRIPTION:
Brian Soby has discovered a vulnerability in Symantec Gateway
Security, allowing malicious people to conduct Cross Site Scripting
attacks.
The problem is that invalid requests for objects in the "/sgmi/"
folder aren't properly sanitised before the URI is returned in an
error page. This can be exploited to include arbitrary HTML and
script code.
The vulnerability affects Symantec Gateway Security 2.0.
SOLUTION:
Symantec has released a hotfix bundle:
ftp://ftp.symantec.com/public/updates/bundle-sgs20.exe
PROVIDED AND/OR DISCOVERED BY:
Brian Soby, Raytheon.
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
----------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]