Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-2212

Опубликовано: 28 апр. 2012
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

McAfee Web Gateway 7.0 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher did not provide configuration details for the vulnerable system, and the observed behavior might be consistent with a configuration that was (perhaps inadvertently) designed to allow access based on Host HTTP headers

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mcafee:web_gateway:7.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 28%
0.00102
Низкий

5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

** DISPUTED ** McAfee Web Gateway 7.0 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher did not provide configuration details for the vulnerable system, and the observed behavior might be consistent with a configuration that was (perhaps inadvertently) designed to allow access based on Host HTTP headers.

EPSS

Процентиль: 28%
0.00102
Низкий

5 Medium

CVSS2

Дефекты

CWE-264