|
Symantec Enterprise Firewall HTTP Pattern Matching Evasion Weakness
Symantec Enterprise Firewall allows HTTP requests containing certain patterns to be blocked. When a URL containing a pattern that matches a pattern blocking rule is submitted by a user behind the firewall, that HTTP request will be blocked. If the same URL is encoded using escaped character sequences, Unicode, or UTF-8, the HTTP request will not be blocked. |
|
|
Privacy Statement |