CVE-2004-0192: XSS
Published Mar 4, 2004
·Updated
Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.
Affected Software
1 affected component
Symantec Gateway Security 5400=2.0
Remediation
Patch Available
Event History
Mar 4, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0192?
CVE-2004-0192 has a high severity due to its potential for cookie theft and session hijacking.
2
How do I fix CVE-2004-0192?
To fix CVE-2004-0192, apply the latest patches released by Symantec for Gateway Security 2.0.
3
Who is affected by CVE-2004-0192?
CVE-2004-0192 affects users of Symantec Gateway Security 5400 version 2.0.
4
What kind of attack does CVE-2004-0192 enable?
CVE-2004-0192 enables cross-site scripting (XSS) attacks that can lead to session hijacking.
5
Is CVE-2004-0192 still a risk today?
CVE-2004-0192 can still pose a risk if users are running unsupported versions of Symantec Gateway Security.