Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-0628

EPSS 0.18% · P40
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2015-0628

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The proxy engine on Cisco Web Security Appliance (WSA) devices allows remote attackers to bypass intended proxying restrictions via a malformed HTTP method, aka Bug ID CSCus79174.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco Web Security Appliance proxy引擎信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Web Security Appliance(WSA)是美国思科(Cisco)公司的一套Web安全设备。该设备提供基于SaaS的访问控制、实时网络报告和追踪、制定安全策略等功能。 Cisco WSA设备的proxy引擎中存在安全漏洞,该漏洞源于程序没有正确处理畸形的HTTP方法。远程攻击者可利用该漏洞绕过既定的代理限制。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2015-0628

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2015-0628

登录查看更多情报信息。

Same Patch Batch · n/a · 2015-02-20 · 18 CVEs total

CVE-2014-3682JBPM jbpm-designer XML外部实体漏洞
CVE-2015-2040WordPress Contact Form DB插件跨站脚本漏洞
CVE-2015-2039WordPress Acobot Live Chat & Contact Form插件跨站请求伪造漏洞
CVE-2015-2035Piwigo SQL注入漏洞
CVE-2015-2034Piwigo 跨站脚本漏洞
CVE-2015-1517Piwigo SQL注入漏洞
CVE-2015-0167textAngular 跨站脚本漏洞
CVE-2014-8115Red Hat KIE Workbench 权限许可和访问控制漏洞
CVE-2014-8114UberFire Framework 权限许可和访问控制漏洞
CVE-2015-0584Cisco Desktop Collaboration Experience DX650端点输入验证漏洞
CVE-2014-0005Red Hat PicketBox和JBossSX 权限许可和访问控制漏洞
CVE-2015-2033Infoblox Network Automation NetMRI Anyterm Daemon 授权问题漏洞
CVE-2015-0881Squid CRLF注入漏洞
CVE-2015-0880AL-Mail32 缓冲区溢出漏洞
CVE-2015-0879AL-Mail32 输入验证漏洞
CVE-2015-0878AL-Mail32 目录遍历漏洞
CVE-2014-5355MIT Kerberos 5 拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2015-0628

No comments yet


Leave a comment