Trend Micro Interscan Applet Trap Domain or IP Bypass Vulnerability
BID:2999
Info
Trend Micro Interscan Applet Trap Domain or IP Bypass Vulnerability
| Bugtraq ID: | 2999 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1026 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 09 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | Discovered and posted to Bugtraq by eDvice Security Services <[email protected]> on July 9, 2001. |
| Vulnerable: |
Trend Micro Interscan Applet Trap 2.0 |
| Not Vulnerable: | |
Discussion
Trend Micro Interscan Applet Trap Domain or IP Bypass Vulnerability
A flaw exists in Trend Micro's Interscan Applet Trap which could enable a user to view an unauthorized web site.
If a host is restricted by domain name, entering the IP address will resolve the unauthorized web site. This vulnerability can be exploited either way, if the host is restricted via IP address, entering the domain name will also return the contents of the unauthorized site.
A flaw exists in Trend Micro's Interscan Applet Trap which could enable a user to view an unauthorized web site.
If a host is restricted by domain name, entering the IP address will resolve the unauthorized web site. This vulnerability can be exploited either way, if the host is restricted via IP address, entering the domain name will also return the contents of the unauthorized site.
Solution / Fix
Trend Micro Interscan Applet Trap Domain or IP Bypass Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.