6.8
CVSSv2

CVE-2004-0192

Published: 15/03/2004 Updated: 11/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote malicious users to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec gateway security 5400 2.0

Exploits

source: wwwsecurityfocuscom/bid/9755/info A vulnerability has been reported to exist in the Symantec Gateway Security Web based management console that may allow a remote user to launch cross-site scripting attacks The issue is reported to exist due to improper sanitizing of user-supplied data It has been reported that HTML and script ...