Security Advisory

CVE-2004-0192

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2004-03-04 05:00:00
Last updated 2024-08-08 00:10:03
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.