7 lines
No EOL
631 B
Text
7 lines
No EOL
631 B
Text
source: https://www.securityfocus.com/bid/9778/info
|
|
|
|
It has been reported that Squid Proxy may be prone to an unauthorized access vulnerability that may allow remote users to bypass access controls resulting in unauthorized access to attacker-specified resources. The vulnerability presents itself when a URI that is designed to access a specific location with a supplied username, contains '%00' characters. This sequence may be placed as part of the username value prior to the @ symbol in the malicious URI.
|
|
|
|
Squid Proxy versions 2.0 to 2.5 STABLE4 are reported to be prone to this vulnerability.
|
|
|
|
http://foo%00@www.example.com/ |