CVE-2001-1152
Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file is in the parentdir, (3) a /./, or (4) URL-encoded characters.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.44% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- baltimore technologies/websweeper
- Source
- cve@mitre.org
References
- http://www.mimesweeper.com/support/technotes/notes/1043.aspVendor Advisory
- http://www.securityfocus.com/archive/1/212283Vendor Advisory
- http://www.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3296Vendor Advisory
- http://www.mimesweeper.com/support/technotes/notes/1043.aspVendor Advisory
- http://www.securityfocus.com/archive/1/212283Vendor Advisory
- http://www.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3296Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.