漏洞信息详情
Clearswift MIMEsweeper For Web可执行文件绕过漏洞
漏洞简介
Clearswift MIMEsweeper For Web (a.k.a. WEBsweeper) 4.0至5.1使得远程攻击者可以通过一个不含有.exe扩展名但是返回可执行文件的URL来绕过过滤。
漏洞公告
参考网址
来源: BID
名称: 15982
链接:http://www.securityfocus.com/bid/15982/
来源: BUGTRAQ
名称: 20051220 Digital Armaments Security Advisory 12.20.2005: WEBsweeper/MIMEsweeper Executable File Content Check bypass Vulnerability
链接:http://www.securityfocus.com/archive/1/archive/1/419904/100/0/threaded
来源: MISC
链接:http://www.digitalarmaments.com/2005161283546323.html
来源: XF
名称: mimesweeper-attachment-filter-bypass(23867)
链接:http://xforce.iss.net/xforce/xfdb/23867
受影响实体
- Clearswift Mimesweeper_for_web:5.1<!--2000-1-1-->
- Clearswift Mimesweeper_for_web:5.0.5<!--2000-1-1-->
- Clearswift Mimesweeper_for_web:5.0.4<!--2000-1-1-->
- Clearswift Mimesweeper_for_web:5.0.3<!--2000-1-1-->
- Clearswift Mimesweeper_for_web:5.0.2<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...