Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WebWasher Classic 绕过安全限制漏洞
Vulnerability Description
WebWasher Classic是一款用于对网页进行过滤的软件。 WebWasher Classic 2.2.1和3.3版本中存在绕过访问控制机制漏洞。 上述版本软件以服务器模式运行时,无法正确处理来自外部系统对localhost的CONNECT请求,这使得远程攻击者可绕过访问限制限制。
CVSS Information
N/A
Vulnerability Type
N/A