Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Internet Security Systems BlackICE Defender Cross-site Scripting Detection Evasion Weakness

A weakness has been in BlackICE Defender has been reported. The problem is said to lie in the detection of cross-site scripting vulnerabilities when embedded within various HTTP requests. Specifically, BlackICE does not match cross-site scripting attacks embedded within PUT and DELETE requests. As a result an attacker may be capable of evading intrusion detection while carrying out these attacks against a target system.







 

Privacy Statement
Copyright 2009, SecurityFocus