Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort prior to 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote malicious users to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cisco secure intrusion detection system |
||
iss realsecure network sensor 5.x |
||
iss realsecure network sensor 6.x |
||
iss realsecure server sensor 5.5 |
||
iss realsecure server sensor 6.0 |
||
snort snort 1.8.1 |
||
cisco catalyst 6000 intrusion detection system module |
||
enterasys dragon 4.x |