WebWasher Classic, is WebWasher's easy-to-use and very effective Internet filter and assistant which runs on the client, a vulnerability in the product allows attackers to cause the product to return arbitrary HTML and/or JavaScript.
Credit:
The information has been provided by Oliver Karow.
Vulnerable systems:
* WebWasher version 3.3 Build 44
* WebWasher version 2.2.1
WebWasher Classic is vulnerable to a XSS attack. If a HTTP GET-Request, containing script code, is sent to the proxy port (default 8080/TCP), an error page is shown, which contains the requested URL in the message body.
Thereby no validation of the requested URL, regarding script code, is done. It should be mentioned that if WebWasher proxy runs in server mode, the proxy port is accessible from the network. If WebWasher proxy runs in client mode, only connections from localhost are possible.