Логотип exploitDog
bind:CVE-2016-5386
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2016-5386

Количество 6

Количество 6

ubuntu логотип

CVE-2016-5386

около 9 лет назад

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 8.1
EPSS: Высокий
redhat логотип

CVE-2016-5386

около 9 лет назад

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 5
EPSS: Высокий
nvd логотип

CVE-2016-5386

около 9 лет назад

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 8.1
EPSS: Высокий
debian логотип

CVE-2016-5386

около 9 лет назад

The net/http package in Go through 1.6 does not attempt to address RFC ...

CVSS3: 8.1
EPSS: Высокий
github логотип

GHSA-9hq4-732f-9vgf

больше 3 лет назад

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 8.1
EPSS: Высокий
oracle-oval логотип

ELSA-2016-1538

около 9 лет назад

ELSA-2016-1538: golang security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-5386

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 8.1
88%
Высокий
около 9 лет назад
redhat логотип
CVE-2016-5386

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 5
88%
Высокий
около 9 лет назад
nvd логотип
CVE-2016-5386

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 8.1
88%
Высокий
около 9 лет назад
debian логотип
CVE-2016-5386

The net/http package in Go through 1.6 does not attempt to address RFC ...

CVSS3: 8.1
88%
Высокий
около 9 лет назад
github логотип
GHSA-9hq4-732f-9vgf

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 8.1
88%
Высокий
больше 3 лет назад
oracle-oval логотип
ELSA-2016-1538

ELSA-2016-1538: golang security, bug fix, and enhancement update (MODERATE)

около 9 лет назад

Уязвимостей на страницу