CVE-2013-2643 | Sophos Web Appliance 3.7.8.1 end-user-/errdoc.php msg cross site scripting (ID 118969 / EDB-24932)
A vulnerability, which was classified as problematic, has been found in Sophos Web Appliance 3.7.8.1. This issue affects some unknown processing of the file end-user-/errdoc.php. The manipulation of the argument msg with the input PHNjcmlwdD5hbGVydCgneHNzJyk7PC9zY3JpcHQ%2bCg%3d%3d leads to cross site scripting.
The identification of this vulnerability is CVE-2013-2643. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.