CVE-2009-0612
https://notcve.org/view.php?id=CVE-2009-0612
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header. Trend Micro InterScan Web Security Virtual Appliance (IWSVA) v3.x e InterScan Web Security Suite (IWSS) v3.x, cuando la autorización básica está habilitada sobre el proxy independiente, reenvía la cabecera de autorización del proxy desde Windows Media Player, lo que permite a servidores Web remotos obtener credenciales ofreciendo una secuencia "media" y capturando esta cabecera. • http://secunia.com/advisories/33891 http://www.securityfocus.com/archive/1/500760/100/0/threaded http://www.securityfocus.com/bid/33687 http://www.securitytracker.com/id?1021716 https://exchange.xforce.ibmcloud.com/vulnerabilities/48681 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •