CVE-2003-1286 Information
Feb 14, 2021
cve
Description
HTTP Proxy in Sambar Server before 6.0 beta 6 when security.ini lacks a 127.0.0.1 proxydeny entry allows remote attackers to send proxy HTTP requests to the Sambar Server’s administrative interface and external web servers by making a \Connection: keep-alive\ request before the proxy requests.
Reference
http://archives.neohapsis.com/archives/bugtraq/2004-04/0353.html http://secunia.com/advisories/9578 http://securitytracker.com/id?1007819 http://www.idefense.com/application/poi/display?id=103&type=vulnerabilities&flashstatus=true http://www.sambar.com/security.htm http://www.securityfocus.com/bid/10256 https://exchange.xforce.ibmcloud.com/vulnerabilities/16054
Share on: