Exploit Squid Proxy 2.4/2.5 - NULL URL Character Unauthorized Access

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
23777
Проверка EDB
  1. Пройдено
Автор
MITCH ADAIR
Тип уязвимости
REMOTE
Платформа
LINUX
CVE
cve-2004-0189
Дата публикации
2004-03-01
Код:
source: https://www.securityfocus.com/bid/9778/info

It has been reported that Squid Proxy may be prone to an unauthorized access vulnerability that may allow remote users to bypass access controls resulting in unauthorized access to attacker-specified resources. The vulnerability presents itself when a URI that is designed to access a specific location with a supplied username, contains '%00' characters. This sequence may be placed as part of the username value prior to the @ symbol in the malicious URI.

Squid Proxy versions 2.0 to 2.5 STABLE4 are reported to be prone to this vulnerability.

http://foo%[email protected]/
 
Источник
www.exploit-db.com

Похожие темы