7.5
CVSSv2

CVE-2000-0116

Published: 29/01/2000 Updated: 10/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Firewall-1 does not properly filter script tags, which allows remote malicious users to bypass the "Strip Script Tags" restriction by including an extra < in front of the SCRIPT tag.

Vulnerable Product Search on Vulmon Subscribe to Product

checkpoint firewall-1 3.0

Exploits

source: wwwsecurityfocuscom/bid/954/info Firewall-1 includes the ability to alter script tags in HTML pages before passing them to the client's browser This alteration invalidates the tag, rendering the script unexecutable by the browser In version 3, this function can be bypassed by adding an extra opening angle bracket The tag will b ...