CNCVE编号:CNCVE-20010520 CVE编号:CAN-2001-0520 安全级别:中 漏洞中文描述: Aladdin eSafe Gateway versions 3.0及其早期版本允许远程攻击者通过在某些特定的HTML标签中嵌入代码来阻止过滤SCRIOT标签,比如:BODY标签中的onload、A标签中的href、BUTTON标签和INPUT标签或任何脚本被定义的其他标签。 漏洞英文描述: Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT tag or other tags defined in other scripts. 漏洞参考: Reference: BUGTRAQ:20010529 Aladdin eSafe Gateway Script-filtering Bypass through HTML tags Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0284.html Reference: XF:esafe-gateway-bypass-filtering(6580) Reference: URL:http://x 系统类型:其他 漏洞类型:输入有效性检查错误