vendor:
Triton
by:
SecurityFocus
9,3
CVSS
HIGH
Remote Command-Execution and HTML Injection
78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')), 79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))
CWE
Product Name: Triton
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
Websense Triton Remote Command-Execution and HTML Injection Vulnerabilities
Websense Triton is prone to a remote command-execution vulnerability and an HTML-injection vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this issue to execute arbitrary commands with SYSTEM-level privileges. Attacker-supplied HTML and script code could be executed in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user; other attacks are also possible.
Mitigation:
Users should apply the patch from the vendor's website and ensure that all user input is properly sanitized.