Flicks Titan Application Firewall Escaped Character Decoding Vulnerability
BID:3551
Info
Flicks Titan Application Firewall Escaped Character Decoding Vulnerability
| Bugtraq ID: | 3551 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2001 12:00AM |
| Updated: | Nov 15 2001 12:00AM |
| Credit: | Submitted by joe user <[email protected]> on November 15, 2001. |
| Vulnerable: |
Flicks Software Titan 5.5 a |
| Not Vulnerable: | |
Discussion
Flicks Titan Application Firewall Escaped Character Decoding Vulnerability
Titan Application Firewall is a firewall product designed to work with Microsoft's IIS webserver. It performs a variety of blocking functions, including the ability to check for patterns within a submitted HTTP request, and block the request if a suspect string is present.
Titan fails to decode escaped characters such as %2e, meaning most rules may be trivially bypassed by submitting variants on the malicious request.
Titan Application Firewall is a firewall product designed to work with Microsoft's IIS webserver. It performs a variety of blocking functions, including the ability to check for patterns within a submitted HTTP request, and block the request if a suspect string is present.
Titan fails to decode escaped characters such as %2e, meaning most rules may be trivially bypassed by submitting variants on the malicious request.
Exploit / POC
Flicks Titan Application Firewall Escaped Character Decoding Vulnerability
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.