When Websense blocks a web site, it returns a web page to the browser stating that the site has been blocked. This error message contains the URL which was requested. Websense does not do any validation or encoding of the URL before returning it in the error message. This allows an attacker to supply a URL that contains JavaScript, ActiveX, VB, etc). This script will run in the context of a server in the trusted domain and combined with other IE flaws can have serious consequences.
Credit:
The information has been provided by Mr. P.Taylor.