7.5
CVE-2005-0316
- EPSS 8.08%
- Veröffentlicht 28.01.2005 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:10:53
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Webwasher ≫ Webwasher Classic Version2.2.1
Webwasher ≫ Webwasher Classic Version3.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 8.08% | 0.941 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://marc.info/?l=bugtraq&m=110693045507245&w=2
http://secunia.com/advisories/14058
http://securitytracker.com/id?1013036
http://www.oliverkarow.de/research/WebWasherCONNECT.txt
http://www.securityfocus.com/bid/12394
https://exchange.xforce.ibmcloud.com/vulnerabilities/19144