Finjan SurfinGate 尾随字符URL过滤器绕过漏洞

漏洞信息详情

Finjan SurfinGate 尾随字符URL过滤器绕过漏洞

漏洞简介

Finjan Software SurfinGate 6.0和6.0 1版本存在漏洞。远程攻击者可以通过主机名部分使用完全合格以\”.\” (点)结尾的域名称(FQDN)中的URL绕过URL访问权限。

漏洞公告

The vendor has confirmed the existence of this issue, and stated that the system is not designed to function as a strong blacklist, as documented in the help file. However, the vendor has made it known that this functionality will be added in addition to resolution of this issue in a future release.

参考网址

来源: BID
名称: 5634
链接:http://www.securityfocus.com/bid/5634

来源: XF
名称: finjan-surfingate-dot-bypass(10037)
链接:http://www.iss.net/security_center/static/10037.php

来源: BUGTRAQ
名称: 20020904 RE: Bypassing the Finjan SurfinGate URL filter
链接:http://archives.neohapsis.com/archives/bugtraq/2002-09/0043.html

来源: BUGTRAQ
名称: 20020904 Bypassing the Finjan SurfinGate URL filter
链接:http://archives.neohapsis.com/archives/bugtraq/2002-09/0032.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享