WEBsweeper Unicode的脚本过滤绕过漏洞

漏洞信息详情

WEBsweeper Unicode的脚本过滤绕过漏洞

漏洞简介

Baltimore Technologies WEBsweeper 4.0和4.02版本不正确的过滤来自HTML页面的Javascript,远程攻击者借助(1)一个额外的前导<和SCRIPT标签之前的一个或多个字符
,或者(2)使用Unicode的标签绕过过滤。

漏洞公告

Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com .
@securityfocus.com>

参考网址

来源: BID
名称: 3173
链接:http://www.securityfocus.com/bid/3173

来源: BID
名称: 3172
链接:http://www.securityfocus.com/bid/3172

来源: BUGTRAQ
名称: 20010812 Various problems in Baltimore’s WEBSweeper Script filter ing
链接:http://www.securityfocus.com/archive/1/203821

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享