Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Squid 安全漏洞
Vulnerability Description
Squid(全称Squid Cache)是一套代理服务器和Web缓存服务器软件。该软件提供缓存万维网、过滤流量、代理上网等功能。 Squid 3.5.18之前版本的mime_header.cc文件中存在安全漏洞。远程攻击者可借助特制的HTTP Host头利用该漏洞绕过既定的同源限制,实施缓存中毒攻击。
CVSS Information
N/A
Vulnerability Type
N/A