Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Aladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Aladdin eSafe MZ头信息文件绕过扫描漏洞
Vulnerability Description
Aladdin的eSafe产品组合由eSate Gateway和eSafe Mail组成,它能针对互联网上的恶意内容来提供最完善的防护功能。 Aladdin eSafe 7.0.17.0版本,当Internet Explorer 6版本或7版本被使用时,远程攻击者通过先放置一个MZ头(又称"EXE info"),然后修改它们的文件名使它们:(1)没有扩展名;(2)具有一个 .txt扩展名;(3)具有一个.jpg扩展名,例如包含CVE-2006-5745的一个文件,以绕过对恶意程序的检测。
CVSS Information
N/A
Vulnerability Type
N/A