20010529 Aladdin eSafe Gateway Script-filtering Bypass through HTML tagsmailing list
http://archives.neohapsis.com/archives/bugtraq/2001-05/0284.html CVE-2001-0520
eSafe Gateway 2.1 - Script-filtering Bypass
Record summary
CVE-2001-0520 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT tag, or (5) any other tag in which scripts can be defined.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBeSafe Gateway 2.1 - Script-filtering BypassExploitDB exploitby eDvice Security ServicesNot analyzed1 file
References
3esafe-gateway-bypass-filtering(6580)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/6580 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0520