Vulnerability Name: | CVE-2007-0563 (CCN-31750) | ||||||||
Assigned: | 2007-01-24 | ||||||||
Published: | 2007-01-24 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in Symantec Web Security (SWS) before 3.0.1.85 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) error messages and (2) blocked page messages produced by SWS. | ||||||||
CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-0563 Source: OSVDB Type: UNKNOWN 32960 Source: OSVDB Type: UNKNOWN 32961 Source: CCN Type: SA23896 Symantec Web Security Two Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 23896 Source: CCN Type: SYM07-001 Symantec Web Security Multiple Vulnerability Source: CONFIRM Type: Patch, Vendor Advisory http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html Source: CCN Type: SECTRACK ID: 1017558 Symantec Web Security Input Validation Hole Permits Cross-Site Scripting and Denial of Service Attacks Source: SECTRACK Type: UNKNOWN 1017558 Source: CCN Type: OSVDB ID: 32960 Symantec Web Security (SWS) Error Page XSS Source: CCN Type: OSVDB ID: 32961 Symantec Web Security (SWS) Blocked Page XSS Source: BID Type: UNKNOWN 22184 Source: CCN Type: BID-22184 Symantec Web Security Multiple Denial of Service And Cross-Site Scripting Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2007-0330 Source: XF Type: UNKNOWN symantec-html-xss(31750) Source: XF Type: UNKNOWN symantec-html-xss(31750) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |