20020311 VirusWall HTTP proxy content scanning circumventionmailing list
http://seclists.org/lists/bugtraq/2002/Mar/0162.html CVE-2002-0440
Trend Micro Interscan VirusWall 3.5/3.6 - Content-Length Scan Bypass
Record summary
CVE-2002-0440 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows malicious web servers to bypass content scanning via a Content-length header set to 0, which is often ignored by HTTP clients.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTrend Micro Interscan VirusWall 3.5/3.6 - Content-Length Scan BypassExploitDB exploitby Jochen Thomas BauerNot analyzed1 file
References
5inside-security.de
http://www.inside-security.de/vwall_cl0.html interscan-viruswall-http-proxy-bypass(8425)vdb entry
http://www.iss.net/security_center/static/8425.php 4265vdb entry
http://www.securityfocus.com/bid/4265 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0440