CVE-2004-2755
Symantec Web Security - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Symantec Web Security 2.5, 3.0.0, and 3.0.1 before build 62 allows remote attackers to inject arbitrary web script or HTML via the query string in blocked URLs that are listed in (1) error or (2) block page messages.
References (6)
Scores
EPSS
0.0116
EPSS Percentile
78.4%
Classification
CWE
CWE-79
Status
draft
Affected Products (3)
symantec/web_security
symantec/web_security
symantec/web_security
Timeline
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026