PT-2009-3403 · Ziproxy · Ziproxy
Robert Auger
·
Publicado
2009-03-04
·
Atualizado
2009-06-18
·
CVE-2009-0804
CVSS v2.0
5.4
Média
| Vetor | AV:N/AC:H/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ziproxy version 2.6.0
Description
The issue allows remote attackers to bypass access controls for certain technologies, such as Flash, Java, and Silverlight, and possibly communicate with restricted intranet sites. This is achieved through a crafted web page that causes a client to send HTTP requests with a modified
Host header when transparent interception mode is enabled.Recommendations
For Ziproxy version 2.6.0, consider disabling transparent interception mode until a patch is available to prevent the modification of the
Host header and mitigate the risk of access control bypass.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ziproxy