Site Archives Cross Site Scripting

SonicWALL Content Filter Security Vulnerability

Posted on October 31st, 2008

GSA Reference Number: AD081031-01
Updated: 11-3-2008

Simply Put: SonicWALL has released an advisory regarding a new vulnerability found in its content filter.  If a user behind a SonicWALL with content filtering enabled clicks on a malicious link, an attacker can cause malicious javascript to be executed through the content filter’s “Blocked Traffic” screen.  This vulnerability only affects SonicWALLs running the Enhanced OS using the content filter with the CFS Block Page.  See below for vulnerable versions.