CVE-2001-1152
Last modified
CVE-2001-1152 is a vulnerability of currently unknown severity. Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file is in the parentdir, (3) a /./, or (4) URL-encoded characters.. EPSS estimates a 2.44% chance of exploitation in the next 30 days.
Description
Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file is in the parentdir, (3) a /./, or (4) URL-encoded characters.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Baltimore Technologies | Websweeper | 4.02 |
References
- http://www.mimesweeper.com/support/technotes/notes/1043.aspVendor Advisory
- http://www.securityfocus.com/archive/1/212283Vendor Advisory
- http://www.mimesweeper.com/support/technotes/notes/1043.aspVendor Advisory
- http://www.securityfocus.com/archive/1/212283Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-1152?
How severe is CVE-2001-1152?
How do I fix CVE-2001-1152?
Are you affected by CVE-2001-1152?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
