CVE-2015-2703: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Websense TRITON AP-WEB before 8.0.0 and V-Series 7.7 appliances allow remote attackers to inject arbitrary web script or HTML via the (1) ws-userip in the ws-encdata parameter to cve-bin/moreBlockInfo.cgi in the Data Security block page or (2) adminmsg parameter to configure/sslui/eva-config/client-cert-importwsoem.html in the Content Gateway, which is not properly handled in an error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2703?
CVE-2015-2703 has a moderate severity level due to the potential for remote code execution through cross-site scripting.
How do I fix CVE-2015-2703?
To fix CVE-2015-2703, upgrade Websense TRITON AP-WEB to version 8.0.0 or higher or V-Series appliances to a patched version beyond 7.7.
What systems are affected by CVE-2015-2703?
CVE-2015-2703 affects Websense TRITON AP-WEB versions prior to 8.0.0 and V-Series appliances version 7.7.
What types of attacks are possible with CVE-2015-2703?
CVE-2015-2703 allows attackers to perform cross-site scripting attacks which can lead to unauthorized actions on behalf of users.
Is CVE-2015-2703 a serious threat?
Yes, CVE-2015-2703 poses a serious threat as it allows remote attackers to inject arbitrary scripts into web pages viewed by users.