NVD

Id
48121  
Name
CVE-2009-0804  
Description
Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.  
Reject
 
CVSS Version
2  
CVSS Score
5.4  
Severity
Medium  
CVSS Base Score
5.4  
CVSS Impact Subscore
6.9  
CVSS Exploit Subscore
4.9  
CVSS Vector
(AV:N/AC:H/Au:N/C:C/I:N/A:N)  
Pub Date
2017-01-07  
Published
2009-03-04  
Modified Date
2009-06-18  
Seq
2009-0804  

Actions