CVE-2016-10256: XSS
The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a reflected XSS vulnerability. A remote attacker can use a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client application. This is a separate vulnerability from CVE-2016-10257.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-10256?
CVE-2016-10256 is a reflected XSS vulnerability in the Symantec ProxySG management console.
How can a remote attacker exploit CVE-2016-10256?
A remote attacker can exploit CVE-2016-10256 by using a crafted management console URL in a phishing attack to inject arbitrary JavaScript code into the management console web client.
What is the severity of CVE-2016-10256?
CVE-2016-10256 has a severity rating of 6.1 (Medium).
What software versions are affected by CVE-2016-10256?
Symantec ProxySG versions 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) are affected by CVE-2016-10256.
How can I fix CVE-2016-10256?
To fix CVE-2016-10256, update the Symantec ProxySG management console to version 6.5.10.6, 6.7.2.1, or later.