Description
Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows malicious web servers to bypass content scanning via a Content-length header set to 0, which is often ignored by HTTP clients.
Affected products
- Trend Micro / interscan_viruswall3.6 – 3.6
- Trend Micro / interscan_viruswall3.51 – 3.51
Exploits & proofs of concept
- exploit-dbTrend Micro Interscan VirusWall 3.5/3.6 - Content-Length Scan Bypassby Jochen Thomas Bauer
Updated 14m ago · 8 sources