Title : Websense "User-Agent" HTTP Header URL Filtering Bypass Vulnerability VUPEN ID : VUPEN/ADV-2007-4210 CVE ID : CVE-2007-6511
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-13
Technical Description
A vulnerability has been identified in Websense, which could be exploited by remote attackers to bypass security checks and restrictions. This issue is caused by a design error when using the "User-Agent" HTTP header to determine whether a request is a URL request or a tunneled protocol request, which could be exploited by attackers to bypass the URL filtering mechanism and gain unauthorized access to restricted and protected pages.