Trend Micro InterScan AppletTrap 2.0 does not properly filter URLs when they are modified in certain ways such as (1) using a double slash (//) instead of a single slash, (2) URL-encoded characters, (3) requesting the IP address instead of the domain name, or (4) using a leading 0 in an octet of an IP address.
References
Configurations
Information
Published : 2001-07-08 21:00
Updated : 2017-12-18 18:29
NVD link : CVE-2001-1026
Mitre link : CVE-2001-1026
JSON object : View
CWE
Products Affected
trend_micro
- interscan_applettrap