Enterasys Networks Information for VU#548515
Multiple intrusion detection systems may be circumvented via %u encoding
- Vendor Information Help Date Notified:
- Statement Date:
- Date Updated: 07 Sep 2001
Dragon Sensor 4.x was affected. Signatures to detect the new IIS UNICODE encoding flaw have been available, and a modification to the Web processing engine is already included in Dragon Sensor 5.0. To obtain dragon products, visit http://dragon.enterasys.com.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.