Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9rm9-22p9-f7rc

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.

EPSS

Процентиль: 71%
0.0068
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 17 лет назад

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.

EPSS

Процентиль: 71%
0.0068
Низкий

Дефекты

CWE-200