XSS detection bypass via unchecked HTTP methods
Published Mar 28, 2022 · Updated Aug 8, 2024
Detection evasion in BlackICE PC Protection 3.6cbd allows remote attackers to bypass XSS alerts with crafted HTTP requests. The Cross Site Scripting Detection component inspects GET and POST requests for a script-tag pattern but omits PUT and DELETE requests, allowing those methods to carry the same pattern without raising an alert. Exploitation requires a protected web server that accepts attacker-controlled script content through PUT or DELETE, and the bounded consequence is an undetected XSS attempt rather than privilege escalation in BlackICE itself.
Summary
What happened
Detection evasion in BlackICE PC Protection 3.6cbd allows remote attackers to bypass XSS alerts with crafted HTTP requests. The Cross Site Scripting Detection component inspects GET and POST requests for a script-tag pattern but omits PUT and DELETE requests, allowing those methods to carry the same pattern without raising an alert. Exploitation requires a protected web server that accepts attacker-controlled script content through PUT or DELETE, and the bounded consequence is an undetected XSS attempt rather than privilege escalation in BlackICE itself.
The record
- CVE
- CVE-2003-5001
- Published
- Mar 28, 2022
- Updated
- Aug 8, 2024
- Vendor
- Internet Security Systems
- Product
- BlackICE PC Protection
- Classifications
- CWE-269
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Mar 28, 2022CVE publishedPublication date reported by the CVE source.
- Aug 8, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=n/a
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- BlackICE PC Protection Cross Site Scripting Evasionproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo