CVE-2009-0612 Information
Feb 14, 2021
cve
Description
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x when basic authorization is enabled on the standalone proxy forwards the Proxy-Authorization header from Windows Media Player which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.
Reference
http://secunia.com/advisories/33891 http://www.securityfocus.com/archive/1/500760/100/0/threaded http://www.securityfocus.com/bid/33687 http://www.securitytracker.com/id?1021716 https://exchange.xforce.ibmcloud.com/vulnerabilities/48681
Share on: