PT-2001-2175 · Trend Micro · Trend Micro Interscan Applettrap

Published

2001-07-09

·

Updated

2017-12-19

·

CVE-2001-1026

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Trend Micro InterScan AppletTrap version 2.0
Description The issue arises from improper URL filtering. Specifically, it does not correctly handle URLs that have been modified in certain ways, such as using a double slash (//) instead of a single slash, utilizing URL-encoded characters, requesting the IP address instead of the domain name, or including a leading 0 in an octet of an IP address.
Recommendations For Trend Micro InterScan AppletTrap version 2.0, consider updating the URL filtering mechanism to properly handle modified URLs, including those with double slashes, URL-encoded characters, IP addresses instead of domain names, and leading zeros in IP address octets. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1026

Affected Products

Trend Micro Interscan Applettrap