Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote malicious users to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using Unicode.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
baltimore technologies websweeper 4.0 |
||
baltimore technologies websweeper 4.02 |