WEBsweeper Script Filtering Bypass Vulnerability
BID:3172
Info
WEBsweeper Script Filtering Bypass Vulnerability
| Bugtraq ID: | 3172 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1157 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was submitted to BugTraq on August 12th, 2001 by "eDvice Security Services" <[email protected]>. |
| Vulnerable: |
Baltimore Technologies WEBsweeper 4.0 2 Baltimore Technologies WEBsweeper 4.0 |
| Not Vulnerable: | |
Discussion
WEBsweeper Script Filtering Bypass Vulnerability
WEBsweeper is an application which sanitizes malicious web content. Suspicious filetypes, hidden mailtos, cookies, scripts, etc. can all be filtered by WEBsweeper users.
WEBsweeper does not adequately filter scripting code from web pages. Malformed variations of <SCRIPT> will not be filtered from the HTML that WEBsweeper generates when a user views a webpage.
This issue will allow malicious scripting code to be executed on the web user, such as in the case of cross-site scripting attacks.
WEBsweeper is an application which sanitizes malicious web content. Suspicious filetypes, hidden mailtos, cookies, scripts, etc. can all be filtered by WEBsweeper users.
WEBsweeper does not adequately filter scripting code from web pages. Malformed variations of <SCRIPT> will not be filtered from the HTML that WEBsweeper generates when a user views a webpage.
This issue will allow malicious scripting code to be executed on the web user, such as in the case of cross-site scripting attacks.
Exploit / POC
WEBsweeper Script Filtering Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
WEBsweeper Script Filtering Bypass Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WEBsweeper Script Filtering Bypass Vulnerability
References:
References:
- WEBsweeper Product Page (Baltimore Technologies)