First published: Fri Apr 24 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Brightmail Gateway Appliance | =7.7 | |
Symantec Brightmail Gateway Appliance | =7.5 | |
Symantec Brightmail Gateway Appliance | <=8.0 | |
Symantec Brightmail Gateway Appliance | =7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0063 is classified as a moderate severity vulnerability due to its potential for unauthorized script injection.
To fix CVE-2009-0063, upgrade the Symantec Brightmail Gateway Appliance to version 8.0.1 or later.
CVE-2009-0063 allows attackers to perform cross-site scripting (XSS) attacks through the Control Center of the appliance.
Users of Symantec Brightmail Gateway Appliance versions 7.5, 7.6, 7.7, and those prior to 8.0.1 are affected by CVE-2009-0063.
The vulnerable software includes Symantec Brightmail Gateway Appliance versions 7.5 through 8.0.