7.5
CVSSv2

CVE-2002-0440

Published: 26/07/2002 Updated: 10/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows malicious web servers to bypass content scanning via a Content-length header set to 0, which is often ignored by HTTP clients.

Vulnerable Product Search on Vulmon Subscribe to Product

trend micro interscan viruswall 3.51

trend micro interscan viruswall 3.6

Exploits

source: wwwsecurityfocuscom/bid/4265/info Trend Micro InterScan VirusWall is a high performance internet gateway virus scanning package It is capable of scanning incoming content over HTTP, SMTP and FTP for viruses and malicious code A vulnerability has been reported in some versions of VirusWall An option exists called "Skip scanning ...