Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f7wx-7f2j-j9m4

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

3proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic authentication, which might cause browsers with incomplete RFC2616/RFC2617 support to use basic cleartext authentication even if NTLM is available, which makes it easier for attackers to steal credentials.

3proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic authentication, which might cause browsers with incomplete RFC2616/RFC2617 support to use basic cleartext authentication even if NTLM is available, which makes it easier for attackers to steal credentials.

EPSS

Процентиль: 58%
0.00373
Низкий

Связанные уязвимости

nvd
почти 19 лет назад

3proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic authentication, which might cause browsers with incomplete RFC2616/RFC2617 support to use basic cleartext authentication even if NTLM is available, which makes it easier for attackers to steal credentials.

debian
почти 19 лет назад

3proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic au ...

EPSS

Процентиль: 58%
0.00373
Низкий