7.5
CVSSv2

CVE-2001-0520

Published: 14/08/2001 Updated: 19/12/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Aladdin eSafe Gateway versions 3.0 and previous versions allows a remote malicious user to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT tag, or (5) any other tag in which scripts can be defined.

Vulnerable Product Search on Vulmon Subscribe to Product

aladdin knowledge systems esafe gateway 3.0

Exploits

source: wwwsecurityfocuscom/bid/2750/info eSafe Gateway is a security utility used for filtering internet content An html file may be crafted to bypass the script-filtering feature offered by eSafe Gateway This is done by simply changing the syntax of the <SCRIPT> function in such a way as to trick the filter into generating html ...