URL Pattern Evasion in Symantec Enterprise Firewall 7.0
CVE-2003-0106

Currently unrated

Key Information:

Vendor

Symantec

Vendor
CVE Published:
2 April 2003

What is CVE-2003-0106?

The HTTP proxy for Symantec Enterprise Firewall version 7.0 is susceptible to a vulnerability that enables proxy users to circumvent URL blocking mechanisms. This is achieved by sending specially crafted requests that are URL-encoded, utilizing escapes, Unicode, or UTF-8 encoding. Consequently, malicious users may exploit this flaw to access prohibited URLs, thereby compromising the integrity of the firewall's filtering capabilities.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.