Sophos UTM 525 Full Guard Cross Site Scripting
Posted by deepcore on March 2, 2016 – 8:02 pm
Inserting an HTML ‘script’ tag into the URL of a web site protected by Sophos UTM 525 yields an error page which contains the ‘script’ tag unfiltered. Executing malicious JavaScript code in the victim’s browser is therefore straightforward.
Post a reply
You must be logged in to post a comment.