CVE-2009-1211
5.8
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:P
Exploitability: 8.6 / Impact: 4.9
Source: NVD
Description
Blue Coat ProxySG, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.
Affected (31)
Products: Bluecoat: Proxysg, Proxysg Sg210 10, Proxysg Sg210 25, Proxysg Sg210 5, Proxysg Sg510 10, Proxysg Sg510 20, Proxysg Sg510 25, Proxysg Sg510 5, Proxysg Sg810 10, Proxysg Sg810 20, Proxysg Sg810 25, Proxysg Sg810 5, Proxysg Sg9000 10, Proxysg Sg9000 20, Proxysg Sg9000 5, Proxysg Va 10, Proxysg Va 15, Proxysg Va 20, Proxysg Va 5
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Related CWEs
References (4)
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.