5.4
CVSSv2

CVE-2009-0802

Published: 04/03/2009 Updated: 18/06/2009
CVSS v2 Base Score: 5.4 | Impact Score: 6.9 | Exploitability Score: 4.9
VMScore: 481
Vector: AV:N/AC:H/Au:N/C:C/I:N/A:N

Vulnerability Summary

Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote malicious users to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qbik wingate 6.0.2_build_1000

qbik wingate 6.0.2_build_1001

qbik wingate 6.1.2

qbik wingate 6.0.1_build_993

qbik wingate 6.2

qbik wingate 6.2.2

qbik wingate 6.1.4

qbik wingate 6.1

qbik wingate 6.1.1.1077

qbik wingate 6.0.0

qbik wingate 6.5.2

qbik wingate 6.0.1_build_995

qbik wingate 6.0.3_build_1005

qbik wingate 6.2.1

qbik wingate 6.1.3