Vulnerabilities > CVE-2007-0563 - Denial of Service And Cross-Site Scripting vulnerability in Symantec Web Security
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Multiple cross-site scripting (XSS) vulnerabilities in Symantec Web Security (SWS) before 3.0.1.85 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) error messages and (2) blocked page messages produced by SWS.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 8 |
Nessus
NASL family | CGI abuses |
NASL id | SYMANTEC_WS_DOS.NASL |
description | According to its banner, the version of Symantec Web Security on the remote host is vulnerable to denial of service and cross-site scripting attacks. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25446 |
published | 2007-06-07 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25446 |
title | Symantec Web Security (SWS) Multiple Vulnerabilities |
code |
|
References
- http://osvdb.org/32960
- http://osvdb.org/32961
- http://secunia.com/advisories/23896
- http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html
- http://securitytracker.com/id?1017558
- http://www.securityfocus.com/bid/22184
- http://www.vupen.com/english/advisories/2007/0330
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31750