Baltimore Technologies MAILsweeper Script Filtering Bypass Vulnerability
BID:3355
Info
Baltimore Technologies MAILsweeper Script Filtering Bypass Vulnerability
| Bugtraq ID: | 3355 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2001 12:00AM |
| Updated: | Sep 22 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on September 22nd, 2001 by "edvice Security Services" <[email protected]>. |
| Vulnerable: |
Baltimore Technologies MAILsweeper for SMTP 4.2.5 Baltimore Technologies MAILsweeper for SMTP 4.2.1 Baltimore Technologies MAILsweeper for SMTP 4.2 |
| Not Vulnerable: |
Baltimore Technologies MAILsweeper for SMTP 4.2.6 |
Discussion
Baltimore Technologies MAILsweeper Script Filtering Bypass Vulnerability
Baltimore Technologies MAILsweeper for SMTP is a commercial application for filtering e-mail content at the gateway level.
MAILsweeper does not adequately filter script code from HTML-enabled e-mail. It is possible to trick MAILsweeper's filter by using HTML-encoded characters. Also, adding an additional "<" to the beginning of a HTML tag which includes script code will be sufficient to bypass the script filter.
Successful exploitation may allow malicious code to be executed on client systems receiving HTML e-mail. This is due to the fact that the malicious e-mail will not be filtered at the gateway level and may affect users within an organization that is using MAILsweeper to filter e-mail content.
Baltimore Technologies MAILsweeper for SMTP is a commercial application for filtering e-mail content at the gateway level.
MAILsweeper does not adequately filter script code from HTML-enabled e-mail. It is possible to trick MAILsweeper's filter by using HTML-encoded characters. Also, adding an additional "<" to the beginning of a HTML tag which includes script code will be sufficient to bypass the script filter.
Successful exploitation may allow malicious code to be executed on client systems receiving HTML e-mail. This is due to the fact that the malicious e-mail will not be filtered at the gateway level and may affect users within an organization that is using MAILsweeper to filter e-mail content.
Exploit / POC
Baltimore Technologies MAILsweeper Script Filtering Bypass Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Baltimore Technologies MAILsweeper Script Filtering Bypass Vulnerability
Solution:
Upgrade to MAILsweeper for SMTP version 4.2.6.
Solution:
Upgrade to MAILsweeper for SMTP version 4.2.6.
References
Baltimore Technologies MAILsweeper Script Filtering Bypass Vulnerability
References:
References:
- MAILsweeper for SMTP Product Page (Baltimore Technologies)
- Various problems in Baltimore MailSweeper Script filtering ("edvice Security Services"
)