Описание
HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server's administrative interface and external web servers, by making a "Connection: keep-alive" request before the proxy requests.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Patch
- Vendor Advisory
- Vendor Advisory
- ExploitPatch
- Vendor Advisory
- Vendor Advisory
- Patch
- Vendor Advisory
- Vendor Advisory
- ExploitPatch
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:sambar:sambar_server:5.0:*:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.0:beta1:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.0:beta2:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.0:beta3:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.0:beta4:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.0:beta5:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.0:beta6:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.1:*:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.1:beta1:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.1:beta2:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.1:beta3:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.1:beta4:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.1:beta5:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.2:*:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:5.3:*:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:6.0:beta1:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:6.0:beta2:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:6.0:beta3:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:6.0:beta4:*:*:*:*:*:*
cpe:2.3:a:sambar:sambar_server:6.0:beta5:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.111
Средний
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server's administrative interface and external web servers, by making a "Connection: keep-alive" request before the proxy requests.
EPSS
Процентиль: 93%
0.111
Средний
7.5 High
CVSS2
Дефекты
NVD-CWE-Other