CVE

Id
3337  
CVE No.
CVE-2001-0523  
Status
Candidate  
Description
eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on vulnerable programs that would otherwise be protected.  
Phase
Modified (20020223-01)  
Votes
ACCEPT(4) Bishop, Cole, Frech, Ziese | NOOP(2) Foat, Wall  
Comments