CVE-2009-0612
17.02.2009, 17:30
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.Enginsight
Vendor | Product | Version |
---|---|---|
trendmicro | interscan_web_security_suite | 2.5 |
trendmicro | interscan_web_security_suite | 3.1 |
trendmicro | interscan_web_security_virtual_appliance | 3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References