The ISAPI Filter plug-in in Websense Enterprise, Websense Web Security, and Websense Web Filter 6.3.3 and earlier, when used in conjunction with a Microsoft ISA or Microsoft Forefront TMG server, allows remote attackers to bypass intended filtering and monitoring activities for web traffic via an HTTP Via header.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-5103
http://mrhinkydink.blogspot.com/2010/05/websense-633-via-bypass.html
http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0376.html