PT-2001-2175 · Trend Micro · Trend Micro Interscan Applettrap
Published
2001-07-09
·
Updated
2017-12-19
·
CVE-2001-1026
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Trend Micro InterScan AppletTrap version 2.0
Description
The issue arises from improper URL filtering. Specifically, it does not correctly handle URLs that have been modified in certain ways, such as using a double slash (//) instead of a single slash, utilizing URL-encoded characters, requesting the IP address instead of the domain name, or including a leading 0 in an octet of an IP address.
Recommendations
For Trend Micro InterScan AppletTrap version 2.0, consider updating the URL filtering mechanism to properly handle modified URLs, including those with double slashes, URL-encoded characters, IP addresses instead of domain names, and leading zeros in IP address octets. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Interscan Applettrap