漏洞信息详情
Finjan SurfinGate 尾随字符URL过滤器绕过漏洞
- CNNVD编号:CNNVD-200212-224
- 危害等级: 高危
- CVE编号:
CVE-2002-1961
- 漏洞类型:
输入验证
- 发布时间:
2002-12-31
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
finjan_software - 漏洞来源:
Vulnerability disc… -
漏洞简介
Finjan Software SurfinGate 6.0和6.0 1版本存在漏洞。远程攻击者可以通过主机名部分使用完全合格以\”.\” (点)结尾的域名称(FQDN)中的URL绕过URL访问权限。
漏洞公告
The vendor has confirmed the existence of this issue, and stated that the system is not designed to function as a strong blacklist, as documented in the help file. However, the vendor has made it known that this functionality will be added in addition to resolution of this issue in a future release.
参考网址
来源: BID
名称: 5634
链接:http://www.securityfocus.com/bid/5634
来源: XF
名称: finjan-surfingate-dot-bypass(10037)
链接:http://www.iss.net/security_center/static/10037.php
来源: BUGTRAQ
名称: 20020904 RE: Bypassing the Finjan SurfinGate URL filter
链接:http://archives.neohapsis.com/archives/bugtraq/2002-09/0043.html
来源: BUGTRAQ
名称: 20020904 Bypassing the Finjan SurfinGate URL filter
链接:http://archives.neohapsis.com/archives/bugtraq/2002-09/0032.html