Overview
Symantec Web Gateway 5.1.1.24, and possibly earlier versions, contains cross-site scripting and SQL injection vulnerabilities.
Description
CVE-2014-1652 - CWE-79: Improper Neutralization of Input During Web Page Generation Symantec Web Gateway 5.1.1.24, and possibly earlier versions, contains a cross-site scripting vulnerability in the filter_date_period, variable and operator parameters of the /spywall/entSummary.php, /spywall/custom_report.php, /spywall/host_spy_report.php and /spywall/repairedclients.php pages. |
Impact
A remote unauthenticated attacker may be able to inject arbitrary script or SQL commands. |
Solution
Apply an Update |
Restrict Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 4.8 | AV:A/AC:L/Au:N/C:P/I:P/A:N |
Temporal | 4.2 | E:H/RL:OF/RC:C |
Environmental | 4.4 | CDP:LM/TD:M/CR:M/IR:M/AR:L |
References
Acknowledgements
Thanks to Min1214 of INFOSEC Inc. working through KrCERT/CC for reporting these vulnerabilities.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2014-1652, CVE-2014-1651 |
Date Public: | 2014-06-16 |
Date First Published: | 2014-06-17 |
Date Last Updated: | 2014-06-17 15:37 UTC |
Document Revision: | 13 |