Описание
Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources from the backend mail system via a request for the resource, aka an Open Reverse Proxy vulnerability.
Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources from the backend mail system via a request for the resource, aka an Open Reverse Proxy vulnerability.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2016-6597
- https://www.pallas.com/advisories/sophos_eas_open_reverse_proxy_vulnerability
- http://packetstormsecurity.com/files/138210/Sophos-Mobile-Control-3.5.0.3-Open-Reverse-Proxy.html
- http://www.securityfocus.com/archive/1/539126/100/0/threaded
- http://www.securityfocus.com/bid/92351
Связанные уязвимости
CVSS3: 8.6
nvd
больше 9 лет назад
Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources from the backend mail system via a request for the resource, aka an Open Reverse Proxy vulnerability.