// For flags

CVE-2009-0801

 

Severity Score

5.4
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

Squid cuando el modo de interceptación trasparente está habilitado, utiliza la cabecera HTTP Host para determinar el punto final remoto, esto permite a atacantes remotos evitar los controles de acceso para Flash, Java, Silverlight y puede que otras tecnologías y permite que se comunique con sitios de intranet restringidos a través de una página Web manipulada que provoca que un cliente envíe solicitudes HTTP con una cabecera Host modificada.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Complete
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-03-04 CVE Reserved
  • 2009-03-04 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
2.7
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "2.7"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
2.7.stable5
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "2.7.stable5"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
2.7.stable6
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "2.7.stable6"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
3.0
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "3.0"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
3.0_pre1
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "3.0_pre1"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
3.0_pre2
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "3.0_pre2"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
3.0_pre3
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "3.0_pre3"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
3.0_stable1
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "3.0_stable1"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
3.0_stable2
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "3.0_stable2"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
3.0_stable3
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "3.0_stable3"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
3.0_stable4
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "3.0_stable4"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
3.0_stable5
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "3.0_stable5"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
3.0_stable6
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "3.0_stable6"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
3.0_stable7
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "3.0_stable7"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
3.0_stable12
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "3.0_stable12"
-
Affected
Squid
Search vendor "Squid"
Squid Web Proxy Cache
Search vendor "Squid" for product "Squid Web Proxy Cache"
3.0_stable13
Search vendor "Squid" for product "Squid Web Proxy Cache" and version "3.0_stable13"
-
Affected