CVE-2001-1152

HIGH
CVSS v3
7.5CVSS v2
0.42% EPSS (exploit probability)
CWE

Description

Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file is in the parentdir, (3) a /./, or (4) URL-encoded characters.

Affected routers (1)

VendorModelMatched viaAffected versionsFixed inPatch Status
Ubiquiti Ubiquiti EdgeRouter 4 Likely Patched

External references