Vulnerabilities > CVE-2003-1286 - Open Proxy Authentication Bypass vulnerability in Sambar

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
sambar
exploit available

Summary

HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server's administrative interface and external web servers, by making a "Connection: keep-alive" request before the proxy requests.

Exploit-Db

descriptionSambar 5.x Open Proxy and Authentication Bypass Vulnerability. CVE-2003-1286. Remote exploit for windows platform
idEDB-ID:24076
last seen2016-02-02
modified2003-01-30
published2003-01-30
reporterDavid Endler
sourcehttps://www.exploit-db.com/download/24076/
titleSambar 5.x Open Proxy and Authentication Bypass Vulnerability