The product does not properly handle when all or part of an input has been URL encoded.
N/A
Threat Mapped score: 0.0
Industry: Finiancial
Threat priority: Unclassified
CVE: CVE-2000-0900
Hex-encoded path traversal variants - "%2e%2e", "%2e%2e%2f", "%5c%2e%2e"
CVE: CVE-2005-2256
Hex-encoded path traversal variants - "%2e%2e", "%2e%2e%2f", "%5c%2e%2e"
CVE: CVE-2004-2121
Hex-encoded path traversal variants - "%2e%2e", "%2e%2e%2f", "%5c%2e%2e"
CVE: CVE-2004-0280
"%20" (encoded space)
CVE: CVE-2003-0424
"%20" (encoded space)
CVE: CVE-2001-0693
"%20" (encoded space)
CVE: CVE-2001-0778
"%20" (encoded space)
CVE: CVE-2002-1831
Crash via hex-encoded space "%20".
CVE: CVE-2000-0671
"%00" (encoded null)
CVE: CVE-2004-0189
"%00" (encoded null)
CVE: CVE-2002-1291
"%00" (encoded null)
CVE: CVE-2002-1031
"%00" (encoded null)
CVE: CVE-2001-1140
"%00" (encoded null)
CVE: CVE-2004-0760
"%00" (encoded null)
CVE: CVE-2002-1025
"%00" (encoded null)
CVE: CVE-2002-1213
"%2f" (encoded slash)
CVE: CVE-2004-0072
"%5c" (encoded backslash) and "%2e" (encoded dot) sequences
CVE: CVE-2004-0847
"%5c" (encoded backslash)
CVE: CVE-2002-1575
"%0a" (overlaps CRLF)
N/A
Phase | Note |
---|---|
Implementation | N/A |
N/A