CVE

Id
3961  
CVE No.
CVE-2001-1157  
Status
Candidate  
Description
Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using Unicode.  
Phase
Proposed (20020315)  
Votes
ACCEPT(1) Green | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese  
Comments
Frech> XF:content-script-bypass-filtering(6580) | XF:content-unicode-bypass-script(6980)