McAfee Email Gateway Cross-Site Scripting Vulnerability (CVE-2016-3969)
McAfee Email Gateway Cross-Site Scripting Vulnerability (CVE-2016-3969)
Release date:
Updated on:
Affected Systems:
McAfee Email Gateway 7.6.x <7.6.404
Description:
CVE (CAN) ID: CVE-2016-3969
McAfee Email Gateway is an enterprise-level Email security solution.
The McAfee Email Gateway (MEG) 7.6.x <7.6.404 has a cross-site scripting vulnerability. When File Filtering is enabled and the action is set to ESERVICES: REPLACE, remote attackers can Email attachments, attackers can inject arbitrary Web scripts or HTML files.
<* Source: Gjoko Krstic (liquidworm@gmail.com)
Link: https://kc.mcafee.com/corporate/index? Page = content & id = SB10153
*>
Suggestion:
Vendor patch:
McAfee
------
McAfee has released a Security Bulletin (SB10153) and corresponding patches for this purpose:
SB10153: Email Gateway 7.6 update fixes cross-site scripting (XSS) vulnerability
Link: https://kc.mcafee.com/corporate/index? Page = content & id = SB10153
This article permanently updates the link address: