CVE-2001-1157: High severity Baltimore Technologies WEBsweeper vulnerability
Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using Unicode.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1157?
CVE-2001-1157 is considered a high severity vulnerability due to its potential to allow remote code execution by bypassing web filtering.
How do I fix CVE-2001-1157?
To fix CVE-2001-1157, upgrade to a patched version of Baltimore Technologies WEBsweeper that addresses the JavaScript filtering issue.
What versions of WEBsweeper are affected by CVE-2001-1157?
CVE-2001-1157 affects both WEBsweeper version 4.0 and 4.02.
What type of attack is facilitated by CVE-2001-1157?
CVE-2001-1157 facilitates remote attacks that bypass JavaScript filtering in HTML pages.
Can CVE-2001-1157 be exploited through Unicode characters?
Yes, CVE-2001-1157 can be exploited by attackers using tags with Unicode characters to bypass filtering.