Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pound HTTP请求窃取漏洞
Vulnerability Description
Pound 是一个HTTP代理服务器。 Pound 1.9.4之前版本中的HTTP请求窃取漏洞,可让远程攻击者通过相冲突的内容长度(Content-length)和传输编码(Transfer-encoding)头,使Web高速缓存中毒、绕过Web应用程序防火墙保护以及执行XSS攻击。
CVSS Information
N/A
Vulnerability Type
N/A