7.5
CVSSv2

CVE-2005-0316

Published: 28/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote malicious users to bypass intended access restrictions.

Vulnerable Product Search on Vulmon Subscribe to Product

webwasher webwasher classic 2.2.1

webwasher webwasher classic 3.3

Exploits

source: wwwsecurityfocuscom/bid/12394/info It is reported that WebWasher Classic is prone to a weakness that may allow remote attackers to connect to arbitrary ports on a vulnerable computer This weakness may be combined with other attacks to exploit latent vulnerabilities An attacker can bypass access controls implemented by the appli ...