Release date: 2011-12-15
Updated on: 2011-12-19
Affected Systems:
Websense Web Security Gateway Anywhere 7.6
Websense Web Filter 7.6
Web Security 7.6
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51088
Websense Tron is a content security solution.
Websense Tron has the HTML injection vulnerability in implementation. Attackers can exploit this vulnerability to execute HTML and script code in affected sites, steal Cookie authentication creden。, or control user sites.
<* Source: Ben Williams
Link: http://www.securityfocus.com/archive/1/520888
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Websense
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.websense.com/global/en/