First published: Wed Mar 04 2009(Updated: )
Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qbik WinGate | =6.0.1_build_993 | |
Qbik WinGate | =6.1.1.1077 | |
Qbik WinGate | =6.5.2 | |
Qbik WinGate | =6.1 | |
Qbik WinGate | =6.0.0 | |
Qbik WinGate | =6.2.1 | |
Qbik WinGate | =6.0.1_build_995 | |
Qbik WinGate | =6.0.2_build_1000 | |
Qbik WinGate | =6.0.3_build_1005 | |
Qbik WinGate | =6.2.2 | |
Qbik WinGate | =6.1.3 | |
Qbik WinGate | =6.1.4 | |
Qbik WinGate | =6.2 | |
Qbik WinGate | =6.1.2 | |
Qbik WinGate | =6.0.2_build_1001 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0802 is classified as a medium severity vulnerability.
To fix CVE-2009-0802, ensure that transparent interception mode is disabled or apply recommended security patches from Qbik.
CVE-2009-0802 affects multiple versions of Qbik WinGate, including versions 6.0.0, 6.0.1, 6.1, 6.2, and 6.5.2.
CVE-2009-0802 can be exploited to bypass access controls and communicate with restricted intranet sites.
Yes, CVE-2009-0802 occurs when the transparent interception mode in Qbik WinGate is enabled.