CVE-2001-1157
Last modified
CVE-2001-1157 is a vulnerability of currently unknown severity. Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using Unicode.. EPSS estimates a 2.44% chance of exploitation in the next 30 days.
Description
Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using Unicode.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Baltimore Technologies | Websweeper | 4.0 |
| Baltimore Technologies | Websweeper | 4.02 |
References
- http://www.securityfocus.com/archive/1/203821Vendor Advisory
- http://www.securityfocus.com/bid/3172Vendor Advisory
- http://www.securityfocus.com/bid/3173Vendor Advisory
- http://www.securityfocus.com/archive/1/203821Vendor Advisory
- http://www.securityfocus.com/bid/3172Vendor Advisory
- http://www.securityfocus.com/bid/3173Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-1157?
How severe is CVE-2001-1157?
How do I fix CVE-2001-1157?
Are you affected by CVE-2001-1157?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
