First published: Wed Apr 26 2006(Updated: )
Websense, when configured to permit access to the dynamic content category, allows local users to bypass intended blocking of the Uncategorized category by appending a "/?" sequence to a URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Websense Websense |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2035 is classified as a medium severity vulnerability.
To fix CVE-2006-2035, ensure proper configuration of Websense to restrict access to the dynamic content category.
CVE-2006-2035 affects users of Websense products that allow access to the dynamic content category.
CVE-2006-2035 is a vulnerability that allows local users to bypass blocking of the Uncategorized category by appending a "/?" to a URL.
No, CVE-2006-2035 requires local user privileges to exploit.