Description
Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra < in front of the SCRIPT tag.
Affected products
- checkpoint / firewall-13.0 – 3.0
Exploits & proofs of concept
- exploit-dbCheck Point Software Firewall-1 3.0 Script - Tag Checking Bypassby Arne Vidstrom
References
Updated 14m ago · 8 sources