2 results (0.003 seconds)

CVSS: 4.0EPSS: 62%CPEs: 1EXPL: 3

Stack-based buffer overflow in the handle_debug_network function in the manager in Websense Content Gateway before 8.0.0 HF02 allows remote administrators to cause a denial of service (crash) via a crafted diagnostic command line request to submit_net_debug.cgi. Desbordamiento del buffer basado en pila en la función handle_debug_network en el gestor en Websense Content Gateway en versiones anteriores a la 8.0.0 HF02, permite a administradores remotos provocar una denegación de servicio (caída) a través de una petición de diagnóstico de línea de comando manipulada a submit_net_debug.cgi. Websense Triton Content Manager version 8.0.0 build 1165 suffers from a stack buffer overflow vulnerability in handle_debug_network. • http://packetstormsecurity.com/files/132968/Websense-Triton-Content-Manager-8.0.0-Build-1165-Buffer-Overflow.html http://seclists.org/fulldisclosure/2015/Aug/8 http://www.securityfocus.com/archive/1/536138/100/0/threaded http://www.securitytracker.com/id/1033263 http://www.websense.com/support/article/kbarticle/v8-0-0-About-Hotfix-02-for-Websense-Content-Gateway https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20150805-0_Websense_Content_Gateway_stack_buffer_overflow_in_handle_ • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 2

Multiple cross-site scripting (XSS) vulnerabilities in monitor/m_overview.ink in Websense Content Gateway before 7.7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) menu or (2) item parameter. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en monitor/m_overview.ink en Websense Content Gateway anterior a v7.7.3, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) menu or (2) item . • https://www.exploit-db.com/exploits/37671 http://secunia.com/advisories/50368 http://www.kb.cert.org/vuls/id/318779 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •