CVE-2012-4604
23.08.2012, 10:32
The TRITON management console in Websense Web Security before 7.6 Hotfix 24 allows remote attackers to bypass authentication and read arbitrary reports via a crafted uid field, in conjunction with a crafted userRoles field, in a cookie, as demonstrated by a request to explorer_wse/favorites.exe.Enginsight
Vendor | Product | Version |
---|---|---|
websense | websense_web_security | 𝑥 ≤ 7.6 |
websense | websense_web_security | 6.3.0 |
websense | websense_web_security | 6.3.1 |
websense | websense_web_security | 6.3.2 |
websense | websense_web_security | 6.3.3 |
websense | websense_web_security | 7.0 |
websense | websense_web_security | 7.1 |
websense | websense_web_security | 7.1.1 |
websense | websense_web_security | 7.5 |
websense | websense_web_security | 7.5.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration