Show filters
32 Total Results
Displaying 21-30 of 32
Sort by:
Attacker Value
Unknown

CVE-2007-6570

Disclosure Date: December 28, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the View URL Database functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 and 3.x before 3.6 SP11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566309.
0
Attacker Value
Unknown

CVE-2007-1225

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in a URL, which might allow remote attackers to conduct unauthorized activities and avoid detection.
0
Attacker Value
Unknown

CVE-2007-1224

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the destination port (:80).
0
Attacker Value
Unknown

CVE-2006-6276

Disclosure Date: December 04, 2006 (last updated February 09, 2024)
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified attack vectors.
0
Attacker Value
Unknown

CVE-2005-3654

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of packets with 0xFF characters to the Telnet port (TCP 23), which corrupts the heap.
0
Attacker Value
Unknown

CVE-2005-4085

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Buffer overflow in BlueCoat (a) WinProxy before 6.1a and (b) the web console access functionality in ProxyAV before 2.4.2.3 allows remote attackers to execute arbitrary code via a long Host: header.
0
Attacker Value
Unknown

CVE-2002-1168

Disclosure Date: November 04, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.
0
Attacker Value
Unknown

CVE-2002-1169

Disclosure Date: November 04, 2002 (last updated February 22, 2025)
IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash.
0
Attacker Value
Unknown

CVE-2002-1167

Disclosure Date: November 04, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.
0
Attacker Value
Unknown

CVE-2002-1001

Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long HTTP request to TCP port 6588 or (2) a SOCKS 4A request to TCP port 1080 with a long DNS hostname.
0