Clearswift MIMEsweeper For Web ActiveX Bypass Vulnerability
BID:14248
Info
Clearswift MIMEsweeper For Web ActiveX Bypass Vulnerability
| Bugtraq ID: | 14248 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2005 12:00AM |
| Updated: | Jul 13 2005 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Clearswift MIMEsweeper For Web 5.0.5 Clearswift MIMEsweeper For Web 5.0.4 Clearswift MIMEsweeper For Web 5.0.3 Clearswift MIMEsweeper For Web 5.0.2 Clearswift MIMEsweeper For Web 5.0.1 Clearswift MIMEsweeper For Web 4.0 |
| Not Vulnerable: |
Clearswift MIMEsweeper For Web 5.1 |
Discussion
Clearswift MIMEsweeper For Web ActiveX Bypass Vulnerability
MIMEsweeper For Web may be exploited to bypass security restrictions.
Reportedly, the application fails to filter specially crafted files containing ActiveX code.
Due to the nature of the application, this issue can create a false sense of security for users protected by it, leading to various attacks.
MIMEsweeper For Web versions prior to 5.1 are affected.
MIMEsweeper For Web may be exploited to bypass security restrictions.
Reportedly, the application fails to filter specially crafted files containing ActiveX code.
Due to the nature of the application, this issue can create a false sense of security for users protected by it, leading to various attacks.
MIMEsweeper For Web versions prior to 5.1 are affected.
Exploit / POC
Clearswift MIMEsweeper For Web ActiveX Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Clearswift MIMEsweeper For Web ActiveX Bypass Vulnerability
Solution:
The vendor has released MIMEsweeper For Web 5.1 to address this issue. Please contact the vendor to obtain a fixed version.
Solution:
The vendor has released MIMEsweeper For Web 5.1 to address this issue. Please contact the vendor to obtain a fixed version.