PT-2001-2175 · Trend Micro · Trend Micro Interscan Applettrap
Publicado
2001-07-09
·
Atualizado
2017-12-19
·
CVE-2001-1026
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Trend Micro InterScan AppletTrap version 2.0
Description
The issue arises from improper URL filtering. Specifically, it does not correctly handle URLs that have been modified in certain ways, such as using a double slash (//) instead of a single slash, utilizing URL-encoded characters, requesting the IP address instead of the domain name, or including a leading 0 in an octet of an IP address.
Recommendations
For Trend Micro InterScan AppletTrap version 2.0, consider updating the URL filtering mechanism to properly handle modified URLs, including those with double slashes, URL-encoded characters, IP addresses instead of domain names, and leading zeros in IP address octets. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Trend Micro Interscan Applettrap