Finjan SurfinGate HTML Filtering Weakness
BID:6702
Info
Finjan SurfinGate HTML Filtering Weakness
| Bugtraq ID: | 6702 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2003 12:00AM |
| Updated: | Jan 27 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Compass Security. |
| Vulnerable: |
Finjan Software SurfinGate 7.0 Finjan Software SurfinGate 6.0 5 Finjan Software SurfinGate 6.0 1 Finjan Software SurfinGate 5.6 |
| Not Vulnerable: | |
Discussion
Finjan SurfinGate HTML Filtering Weakness
The HTML filter included with Finjan SurfinGate does not sufficiently recognize certain types of malicious HTML which may pose a threat to end users.
As a result, end users may be exposed to attacks which utilize malicious HTML to cause a denial of service or impact the user in other ways.
The HTML filter included with Finjan SurfinGate does not sufficiently recognize certain types of malicious HTML which may pose a threat to end users.
As a result, end users may be exposed to attacks which utilize malicious HTML to cause a denial of service or impact the user in other ways.
Exploit / POC
Finjan SurfinGate HTML Filtering Weakness
No exploit is required.
No exploit is required.
Solution / Fix
Finjan SurfinGate HTML Filtering Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Finjan SurfinGate HTML Filtering Weakness
References:
References:
- SurfinGate Product Page (Finjan Software)
- RE: Tech Article: HTTP Content Filter Analysis - Finjan SurfinGate V5.6 ("Menashe Eliezer"
) - Tech Article: HTTP Content Filter Analysis - Finjan SurfinGate v5.6 ("[email protected]"
)