Multiple HTTP Proxy HTTP Host Header Incorrect Relay Behavior Vulnerability

Multiple HTTP proxy implementations are prone to an information-disclosure vulnerability related to the interpretation of the 'Host' HTTP header. Specifically, this issue occurs when the proxy makes a forwarding decision based on the 'Host' HTTP header instead of the destination IP address.

Attackers may exploit this issue to obtain sensitive information such as internal intranet webpages. Additional attacks may also be possible.


 

Privacy Statement
Copyright 2010, SecurityFocus