CVE-2014-9711: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Investigative Reports in Websense TRITON AP-WEB before 8.0.0 and Web Security and Filter, Web Security Gateway, and Web Security Gateway Anywhere 7.8.3 before Hotfix 02 and 7.8.4 before Hotfix 01 allow remote attackers to inject arbitrary web script or HTML via the (1) ReportName (Job Name) parameter to the Explorer report scheduler (cgi-bin/WsCgiExplorerSchedule.exe) in the Job Queue or the col parameter to the (2) Names or (3) Anonymous (explorerwse/exploreranon.exe) summary report page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9711?
CVE-2014-9711 has a medium severity rating due to its potential for exploitation through cross-site scripting attacks.
How do I fix CVE-2014-9711?
To fix CVE-2014-9711, upgrade Websense TRITON AP-WEB to version 8.0.0 or apply the hotfixes for Web Security products as specified by the vendor.
What types of attacks does CVE-2014-9711 enable?
CVE-2014-9711 enables remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts.
Which versions of Websense are affected by CVE-2014-9711?
CVE-2014-9711 affects Websense TRITON AP-WEB versions prior to 8.0.0 and versions of Web Security and Filter, Web Security Gateway, and Web Security Gateway Anywhere prior to version 7.8.4.
Can CVE-2014-9711 be exploited without authentication?
Yes, CVE-2014-9711 can be exploited by remote attackers without requiring authentication.