Логотип exploitDog
bind:CVE-2016-1000108
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2016-1000108

Количество 4

Количество 4

ubuntu логотип

CVE-2016-1000108

около 6 лет назад

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2016-1000108

около 6 лет назад

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2016-1000108

около 6 лет назад

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42gq-6jpg-qgvv

больше 3 лет назад

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-1000108

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 6.1
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2016-1000108

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 6.1
1%
Низкий
около 6 лет назад
debian логотип
CVE-2016-1000108

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 ...

CVSS3: 6.1
1%
Низкий
около 6 лет назад
github логотип
GHSA-42gq-6jpg-qgvv

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу