PT-2007-2646 · Netproxy · Netproxy
Craig Heffner
·
Published
2007-03-02
·
Updated
2017-10-11
·
CVE-2007-1225
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NetProxy version 4.03
Description
The connection log file implementation does not record requests that omit http:// in a URL, which might allow remote attackers to conduct unauthorized activities and avoid detection.
Recommendations
For NetProxy version 4.03, update the connection log file implementation to record all requests, including those that omit http:// in a URL, to prevent unauthorized activities from going undetected.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netproxy