← Back

CVE-2009-0802

nvd nist
Published: Mar 4, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.4
Vector
AV:N/AC:H/Au:N/C:C/I:N/A:N
Exploitability: 4.9 / Impact: 6.9
Source: NVD

Description

Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

Affected (15)

Products: Qbik: Wingate
1 product
Wingate
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Qbik
Version 6.0.0
Version 6.0.1_build_993
Version 6.0.1_build_995
Version 6.0.2_build_1000
Version 6.0.2_build_1001
Version 6.0.3_build_1005
Version 6.1.1.1077
Version 6.1.2
Version 6.1.3
Version 6.1.4
Version 6.1
Version 6.2.1
Version 6.2.2
Version 6.2
Version 6.5.2

Related CWEs

References (4)

Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.