RULE(RULE ID:316144)

Rule General Information
Release Date: 2015-03-03
Rule Name: Symantec Messaging Gateway Management Console Cross Site Scripting Vulnerability (CVE-2014-1648)
Severity:
CVE ID:
Rule Protection Details
Description: Cross-site scripting (XSS) vulnerability in brightmail/setting/compliance/DlpConnectFlow$view.flo in the management console in Symantec Messaging Gateway 10.x before 10.5.2 allows remote attackers to inject arbitrary web script or HTML via the displayTab parameter.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows
Reference: SecurityFocusBID:66966
SecurityTrackerID:1030136
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&