Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in the Web Administrator in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allow remote attackers to inject arbitrary web script or HTML via the (1) FileName, (2) IsolatedMessageID, (3) ServerName, (4) Dictionary, (5) Scoring, and (6) MessagePart parameters to web/msgList/viewmsg/actions/msgAnalyse.asp; the (7) Queue, (8) FileName, (9) IsolatedMessageID, and (10) ServerName parameters to actions/msgForwardToRiskFilter.asp and viewHeaders.asp in web/msgList/viewmsg/; and (11) the subject in an e-mail message that is held in a Queue.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Websense Email Security Web Administrator前端跨站脚本漏洞
Vulnerability Description
Websense Email Security是综合的邮件安全软件,对邮件和Web 2.0的混合威胁提供防护。 Websense Email Security默认监听于TCP/8181端口上的Web Administrator管理前端没有正确地过滤某些变量便返回给了用户,远程攻击者可以通过提交恶意的HTTP请求执行跨站脚本攻击;此外没有正确地过滤邮件的Subject字段便在Web Administrator前端显示,远程攻击者可以在标题中注入类似于"<script>alert('X')</script>的
CVSS Information
N/A
Vulnerability Type
N/A