PT-2009-3403 · Ziproxy · Ziproxy
Robert Auger
·
Published
2009-03-04
·
Updated
2009-06-18
·
CVE-2009-0804
CVSS v2.0
5.4
Medium
| Vector | AV:N/AC:H/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ziproxy version 2.6.0
Description
The issue allows remote attackers to bypass access controls for certain technologies, such as Flash, Java, and Silverlight, and possibly communicate with restricted intranet sites. This is achieved through a crafted web page that causes a client to send HTTP requests with a modified
Host header when transparent interception mode is enabled.Recommendations
For Ziproxy version 2.6.0, consider disabling transparent interception mode until a patch is available to prevent the modification of the
Host header and mitigate the risk of access control bypass.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ziproxy