CVE-2001-1152: High severity Baltimore Technologies WEBsweeper vulnerability
Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file is in the parentdir, (3) a /./, or (4) URL-encoded characters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1152?
CVE-2001-1152 has a moderate severity level as it allows unauthorized connections to web servers by bypassing URL blacklists.
How do I fix CVE-2001-1152?
To fix CVE-2001-1152, upgrade to a newer version of Baltimore Technologies WEBsweeper that addresses this vulnerability.
What systems are affected by CVE-2001-1152?
CVE-2001-1152 specifically affects Baltimore Technologies WEBsweeper version 4.02.
What is the impact of CVE-2001-1152?
The impact of CVE-2001-1152 is that it allows remote attackers to bypass blacklist restrictions and access unauthorized websites.
Can CVE-2001-1152 be exploited remotely?
Yes, CVE-2001-1152 can be exploited remotely by modifying the requested URL to bypass security measures.