First published: Wed Jan 10 2018(Updated: )
The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client application. This is a separate vulnerability from CVE-2016-10257.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom ProxySG | >=6.5<6.5.10.6 | |
Broadcom ProxySG | >=6.7<6.7.2.1 | |
Broadcom ProxySG | =6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10256 is a reflected XSS vulnerability in the Symantec ProxySG management console.
A remote attacker can exploit CVE-2016-10256 by using a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client.
CVE-2016-10256 has a severity rating of 6.1 (Medium).
Symantec ProxySG versions 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) are affected by CVE-2016-10256.
To fix CVE-2016-10256, update the Symantec ProxySG management console to version 6.5.10.6, 6.7.2.1, or later.