eSafe Gateway Unicode Script-filtering Bypass Vulnerability
BID:2801
Info
eSafe Gateway Unicode Script-filtering Bypass Vulnerability
| Bugtraq ID: | 2801 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 29 2001 12:00AM |
| Updated: | May 29 2001 12:00AM |
| Credit: | This vulnerability was posted to BugTraq by eDvice Security Services <[email protected]> on May 20th, 2001. |
| Vulnerable: |
Aladdin Knowledge Systems eSafe Gateway 3.0 |
| Not Vulnerable: | |
Discussion
eSafe Gateway Unicode Script-filtering Bypass Vulnerability
eSafe Gateway is a security utility used for filtering internet content.
An html file may be crafted to bypass the script-filtering feature offered by eSafe Gateway. This is done by simply encoding the <SCRIPT> tag in Unicode format, such that the filter ignores the call to execute the script.
eSafe Gateway is a security utility used for filtering internet content.
An html file may be crafted to bypass the script-filtering feature offered by eSafe Gateway. This is done by simply encoding the <SCRIPT> tag in Unicode format, such that the filter ignores the call to execute the script.
Exploit / POC
eSafe Gateway Unicode Script-filtering Bypass Vulnerability
script38a.zip courtesy eDvice Security Services <[email protected]>
script38a.zip courtesy eDvice Security Services <[email protected]>
Solution / Fix
eSafe Gateway Unicode Script-filtering Bypass Vulnerability
Solution:
The vendor has been notified of this issue and states that it will be fixed in the new version.
Solution:
The vendor has been notified of this issue and states that it will be fixed in the new version.
References
eSafe Gateway Unicode Script-filtering Bypass Vulnerability
References:
References:
- Vulnerability Discovered in Aladdin's eSafe Gateway (eDvice Security Services)