CVE-2008-7312: Input Validation
The Filtering Service in Websense Enterprise 5.2 through 6.3 does not consider the IP address during URL categorization, which makes it easier for remote attackers to bypass filtering via an HTTP request, as demonstrated by a request to a compromised server associated with a specific IP address.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7312?
CVE-2008-7312 has been classified as a medium severity vulnerability due to its potential to bypass URL filtering.
How do I fix CVE-2008-7312?
To mitigate CVE-2008-7312, upgrade your Websense Enterprise software to version 6.4 or later, which addresses this vulnerability.
What versions of Websense Enterprise are affected by CVE-2008-7312?
CVE-2008-7312 affects Websense Enterprise versions 5.2 through 6.3.
What type of attack does CVE-2008-7312 allow?
CVE-2008-7312 allows remote attackers to bypass the URL filtering service by manipulating HTTP requests.
Is CVE-2008-7312 a network-based vulnerability?
Yes, CVE-2008-7312 can be exploited remotely over the network to circumvent filtering mechanisms.