Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Squid 安全漏洞
Vulnerability Description
Squid(全称Squid Cache)是一套代理服务器和Web缓存服务器软件。该软件提供缓存万维网、过滤流量、代理上网等功能。 Squid 3.5.18之前版本和4.0.10之前4.x版本中的client_side.cc文件存在安全漏洞,该漏洞源于当用户提供absolute-URI时,程序没有正确忽略Host头。远程攻击者可通过提供HTTP请求利用该漏洞实施缓存中毒攻击。
CVSS Information
N/A
Vulnerability Type
N/A