CVE-2001-1157
Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using Unicode.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.44% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- baltimore technologies/websweeper
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/203821Vendor Advisory
- http://www.securityfocus.com/bid/3172Vendor Advisory
- http://www.securityfocus.com/bid/3173Vendor Advisory
- http://www.securityfocus.com/archive/1/203821Vendor Advisory
- http://www.securityfocus.com/bid/3172Vendor Advisory
- http://www.securityfocus.com/bid/3173Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.