Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra < in front of the SCRIPT tag.
Loading...
Loading...
Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra < in front of the SCRIPT tag.
January 29, 2000
April 16, 2026
Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
Check Point Software Firewall-1 3.0 Script - Tag Checking Bypass
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2000-0116
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.