Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using Unicode.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2002-03-15T05:00:00
Updated: 2024-08-08T04:44:07.933Z
Reserved: 2002-03-15T00:00:00
Link: CVE-2001-1157
Vulnrichment
No data.
NVD
Status : Modified
Published: 2001-08-12T04:00:00.000
Modified: 2024-11-20T23:37:01.543
Link: CVE-2001-1157
Redhat
No data.