7.5

CVE-2005-0173

squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SquidSquid Version2.0.patch1
SquidSquid Version2.0.patch2
SquidSquid Version2.0.pre1
SquidSquid Version2.0.release
SquidSquid Version2.1.patch1
SquidSquid Version2.1.patch2
SquidSquid Version2.1.pre1
SquidSquid Version2.1.pre3
SquidSquid Version2.1.pre4
SquidSquid Version2.1.release
SquidSquid Version2.2.devel3
SquidSquid Version2.2.devel4
SquidSquid Version2.2.pre1
SquidSquid Version2.2.pre2
SquidSquid Version2.2.stable1
SquidSquid Version2.2.stable2
SquidSquid Version2.2.stable3
SquidSquid Version2.2.stable4
SquidSquid Version2.2.stable5
SquidSquid Version2.3.devel2
SquidSquid Version2.3.devel3
SquidSquid Version2.3.stable1
SquidSquid Version2.3.stable2
SquidSquid Version2.3.stable3
SquidSquid Version2.3.stable4
SquidSquid Version2.3.stable5
SquidSquid Version2.4.stable1
SquidSquid Version2.4.stable2
SquidSquid Version2.4.stable3
SquidSquid Version2.4.stable4
SquidSquid Version2.4.stable6
SquidSquid Version2.4.stable7
SquidSquid Version2.5.stable1
SquidSquid Version2.5.stable2
SquidSquid Version2.5.stable3
SquidSquid Version2.5.stable4
SquidSquid Version2.5.stable5
SquidSquid Version2.5.stable6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.69% 0.805
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P