CVE-2001-1152 Information

Description

Baltimore Technologies WEBsweeper 4.02 when used to manage URL blacklists allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL including (1) a // (double slash) (2) a /SUBDIR/.. where the desired file is in the parentdir (3) a /./ or (4) URL-encoded characters.

Reference

http://www.mimesweeper.com/support/technotes/notes/1043.asp http://www.securityfocus.com/archive/1/212283 http://www.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3296

Share on: