// For flags

CVE-2004-0189

Squid Proxy 2.4/2.5 - NULL URL Character Unauthorized Access

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.

La función de decodificación de URL "%xx" en Squid 2.5STABLE4 y anteriores permite a atacantes remotos saltarse las listas de control de acceso (ACL) url_regex mediante una URL con un carácter nulo ("%00"), lo que hace que Squid use sólo un parte de la URL solicitada para compararla con la lista de control de acceso.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2004-03-01 First Exploit
  • 2004-03-03 CVE Reserved
  • 2004-03-15 CVE Published
  • 2023-08-09 EPSS Updated
  • 2024-08-08 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Squid
Search vendor "Squid"
Squid
Search vendor "Squid" for product "Squid"
2.0_patch2
Search vendor "Squid" for product "Squid" and version "2.0_patch2"
-
Affected
Squid
Search vendor "Squid"
Squid
Search vendor "Squid" for product "Squid"
2.1_patch2
Search vendor "Squid" for product "Squid" and version "2.1_patch2"
-
Affected
Squid
Search vendor "Squid"
Squid
Search vendor "Squid" for product "Squid"
2.3_stable5
Search vendor "Squid" for product "Squid" and version "2.3_stable5"
-
Affected
Squid
Search vendor "Squid"
Squid
Search vendor "Squid" for product "Squid"
2.4
Search vendor "Squid" for product "Squid" and version "2.4"
-
Affected
Squid
Search vendor "Squid"
Squid
Search vendor "Squid" for product "Squid"
2.4_stable7
Search vendor "Squid" for product "Squid" and version "2.4_stable7"
-
Affected
Squid
Search vendor "Squid"
Squid
Search vendor "Squid" for product "Squid"
2.5_stable3
Search vendor "Squid" for product "Squid" and version "2.5_stable3"
-
Affected
Squid
Search vendor "Squid"
Squid
Search vendor "Squid" for product "Squid"
2.5_stable4
Search vendor "Squid" for product "Squid" and version "2.5_stable4"
-
Affected