CVE-2006-6982 Information

Description

3proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic authentication which might cause browsers with incomplete RFC2616/RFC2617 support to use basic cleartext authentication even if NTLM is available which makes it easier for attackers to steal credentials.

Reference

http://3proxy.ru/0.5.3g/Changelog.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/38205

Share on: