CVE-2004-2755: XSS
Cross-site scripting (XSS) vulnerability in Symantec Web Security 2.5, 3.0.0, and 3.0.1 before build 62 allows remote attackers to inject arbitrary web script or HTML via the query string in blocked URLs that are listed in (1) error or (2) block page messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2755?
CVE-2004-2755 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2004-2755?
To fix CVE-2004-2755, upgrade Symantec Web Security to version 3.0.1 build 62 or later.
What types of attacks can exploit CVE-2004-2755?
CVE-2004-2755 can be exploited by remote attackers to inject arbitrary web scripts or HTML into error and block page messages.
Which versions of Symantec Web Security are affected by CVE-2004-2755?
CVE-2004-2755 affects Symantec Web Security versions 2.5, 3.0.0, and 3.0.1 prior to build 62.
What are the potential impacts of CVE-2004-2755?
The potential impacts of CVE-2004-2755 include unauthorized access and manipulation of session information due to XSS.