漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Tinyproxy - Stathost Detection Bypass via Host Header Manipulation
Vulnerability Description
Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorized access to internal proxy statistics or misroute requests as transparent proxy connections to circumvent access controls.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
使用欺骗进行的认证绕过
Vulnerability Title
tinyproxy 授权问题漏洞
Vulnerability Description
tinyproxy是Tinyproxy团队开源的一个小型、高效的 HTTP/SSL 代理守护程序。 tinyproxy 1.11.3及之前版本存在授权问题漏洞,该漏洞源于stathost检测中对Host标头验证不当,可能导致未经身份验证的攻击者通过注入匹配的Host标头或端口操纵绕过检测访问stats页面,以及远程攻击者触发未授权访问内部代理统计信息或通过透明代理连接错误路由请求以绕过访问控制。
CVSS Information
N/A
Vulnerability Type
N/A