Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
3proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic authentication, which might cause browsers with incomplete RFC2616/RFC2617 support to use basic cleartext authentication even if NTLM is available, which makes it easier for attackers to steal credentials.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
3proxy权限问题漏洞
Vulnerability Description
3proxy 0.5 to 0.5.2版本没有在基础权限以前提供NTLM权限, 这会引起及时在NTLM可利用的情况下,RFC2616/RFC2617支持不足的浏览器会运行基础空白文本权限,这会使攻击者易于窃取证书。
CVSS Information
N/A
Vulnerability Type
N/A