vendor:
Internet access management system
by:
Nahuel Grisolia
7,5
CVSS
HIGH
Filter Bypass
20
CWE
Product Name: Internet access management system
Affected Version From: All
Affected Version To: All
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
Websense Proxy Filter Bypass
An authenticated user could successfully bypass URL restrictions and access unauthorized sites by issuing a specially crafted request. To be completely stealth, just remove ?a? char and no log will be recorded. Limitations: It's only possible to issue GET requests and it will only work if the remote Webserver accepts malformed GET requests specifying a Content-Length, like Facebook, Hotmail, Etc. The attacker might use a WebProxy with this property, completely bypassing the filter.
Mitigation:
No patch available yet