PT-2007-2646 · Netproxy · Netproxy

Craig Heffner

·

Published

2007-03-02

·

Updated

2017-10-11

·

CVE-2007-1225

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NetProxy version 4.03
Description The connection log file implementation does not record requests that omit http:// in a URL, which might allow remote attackers to conduct unauthorized activities and avoid detection.
Recommendations For NetProxy version 4.03, update the connection log file implementation to record all requests, including those that omit http:// in a URL, to prevent unauthorized activities from going undetected.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1225

Affected Products

Netproxy