Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-0174

Опубликовано: 07 фев. 2005
Источник: nvd
CVSS2: 5
EPSS Средний

Описание

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:squid:squid:2.5.6:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable2:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable5:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable6:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable7:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_.stable1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_.stable3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_.stable4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_.stable5:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_.stable6:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_stable3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_stable4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_stable9:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.50775
Средний

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 21 года назад

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

redhat
больше 21 года назад

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

debian
больше 21 года назад

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cach ...

github
около 4 лет назад

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

EPSS

Процентиль: 99%
0.50775
Средний

5 Medium

CVSS2

Дефекты

NVD-CWE-Other