7.5
CVSSv2

CVE-2001-0521

Published: 14/08/2001 Updated: 19/12/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Aladdin eSafe Gateway versions 3.0 and previous versions allows a remote malicious user to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.

Vulnerable Product Search on Vulmon Subscribe to Product

aladdin knowledge systems esafe gateway 3.0

Exploits

source: wwwsecurityfocuscom/bid/2801/info eSafe Gateway is a security utility used for filtering internet content An html file may be crafted to bypass the script-filtering feature offered by eSafe Gateway This is done by simply encoding the <SCRIPT> tag in Unicode format, such that the filter ignores the call to execute the scri ...