漏洞信息详情
arbitrarySymantec Web Security Block Page Message跨站脚本漏洞
- CNNVD编号:CNNVD-200412-1004
- 危害等级: 中危
- CVE编号:
CVE-2004-2755
- 漏洞类型:
跨站脚本
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2004-12-31
- 厂 商:
symantec - 漏洞来源:
The disclosure of … -
漏洞简介
Symantec Web Security build 62以前的2.5,3.0.0,和3.0.1版本存在跨站脚本(XSS)漏洞。远程攻击者借助查询字符串注入任意web脚本或者HTML,该字符串在列出(1)错误或(2)块页消息的被拦截的URLs中。
漏洞公告
Symantec has reported that this issue has been addressed in Symantec Web Security version 3.0.1 build 62. Users are advised to contact the vendor to obtain the fixed version.
参考网址
来源: XF
名称: symantec-websecurity-blocked-xss(14825)
链接:http://xforce.iss.net/xforce/xfdb/14825
来源: SECTRACK
名称: 1008711
链接:http://www.securitytracker.com/alerts/2004/Jan/1008711.html
来源: BID
名称: 9418
链接:http://www.securityfocus.com/bid/9418
来源: OSVDB
名称: 6754
链接:http://www.osvdb.org/6754
来源: securityresponse.symantec.com
链接:http://securityresponse.symantec.com/avcenter/security/Content/2004.01.13.html
来源: SECUNIA
名称: 10618
链接:http://secunia.com/advisories/10618