CVE-2005-0316: High severity Webwasher WebWasher Classic vulnerability
Published Jan 28, 2005
·Updated
WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.
Affected Software
2 affected components
Webwasher WebWasher Classic=2.2.1
Webwasher WebWasher Classic=3.3
Remediation
Patch Available
Patch Available
Event History
Jan 28, 2005
CVE Published
05:00 AM
Feb 10, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0316?
The severity of CVE-2005-0316 is rated high at 7.5.
2
How do I fix CVE-2005-0316?
To fix CVE-2005-0316, apply the available patch for WebWasher Classic.
3
What software is affected by CVE-2005-0316?
CVE-2005-0316 affects WebWasher Classic versions 2.2.1 and 3.3 when running in server mode.
4
What type of vulnerability is CVE-2005-0316?
CVE-2005-0316 is a local access control vulnerability that allows remote attackers to bypass restrictions.
5
What are the potential impacts of CVE-2005-0316?
CVE-2005-0316 could allow remote attackers to access sensitive data and functionalities due to improper handling of CONNECT requests.