Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-2060

EPSS 0.39% · P60
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-2060

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Google Chrome 程序"http_transaction_winhttp.cc" "HTTP Host"报头中间人攻击漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Google Chrome 程序"http_transaction_winhttp.cc" "HTTP Host"报头存在安全漏洞,在处理到代理的CONNECT请求后的(1)4xx;(2)5xx响应时存在错误,如果攻击者能够对使用代理服务器的例程执行中间人攻击,就可以从用户所访问的站点窃取敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-2060

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-2060

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-06-15 · 17 CVEs total

CVE-2009-2057Microsoft Internet Explorer 授权问题漏洞
CVE-2009-2058Apple Safari "HTTP Host"报头中间人攻击漏洞
CVE-2009-2059Opera "HTTP Host"报头中间人攻击漏洞
CVE-2009-2061Mozilla Firefox "HTTP CONNECT"响应中间人攻击漏洞
CVE-2009-2062Apple Safari "HTTP CONNECT"响应中间人攻击漏洞
CVE-2009-2063Opera "HTTP CONNECT"响应中间人攻击漏洞
CVE-2009-2064Microsoft Internet Explorer HTTPS 安全绕过和中间人攻击漏洞
CVE-2009-2065Mozilla Firefox "http content" 安全绕过和中间人攻击漏洞
CVE-2009-2066Apple Safari "http content" 安全绕过和中间人攻击漏洞
CVE-2009-2067Opera "http content" 安全绕过和中间人攻击漏洞
CVE-2009-2068Opera 'http content'安全绕过和中间人攻击漏洞
CVE-2009-2069Microsoft Internet Explorer 授权问题漏洞
CVE-2009-2070Opera 隐藏证书中间人攻击漏洞
CVE-2009-2071Google Chrome 隐藏证书中间人攻击漏洞
CVE-2009-2072Apple Safari 隐藏证书中间人攻击漏洞
CVE-2009-2073Linksys WRT160N无线路由器跨站请求伪造漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-2060

No comments yet


Leave a comment