eSafe Gateway Unicode Script-filtering Bypass Vulnerability

eSafe Gateway is a security utility used for filtering internet content.

An html file may be crafted to bypass the script-filtering feature offered by eSafe Gateway. This is done by simply encoding the <SCRIPT> tag in Unicode format, such that the filter ignores the call to execute the script.


 

Privacy Statement
Copyright 2010, SecurityFocus