CVE-2012-2566: Medium severity bloxx web filtering vulnerability
Bloxx Web Filtering before 5.0.14 does not properly interpret X-Forwarded-For headers during access-control and logging operations for HTTPS connection attempts, which allows remote attackers to bypass intended IP address and domain restrictions, and trigger misleading log entries, via a crafted header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2566?
CVE-2012-2566 is considered to have a high severity due to its potential to allow unauthorized access and manipulation of logs.
How do I fix CVE-2012-2566?
To fix CVE-2012-2566, you should upgrade to Bloxx Web Filtering version 5.0.14 or later, which addresses this vulnerability.
What vulnerability does CVE-2012-2566 address?
CVE-2012-2566 addresses the improper handling of X-Forwarded-For headers in Bloxx Web Filtering that can lead to access-control bypass.
What systems are affected by CVE-2012-2566?
CVE-2012-2566 affects versions of Bloxx Web Filtering prior to 5.0.14.
Can CVE-2012-2566 be exploited remotely?
Yes, CVE-2012-2566 can be exploited remotely, allowing attackers to bypass intended IP address and domain restrictions.