CVE-2014-9304
07.12.2014, 21:59
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.Enginsight
Vendor | Product | Version |
---|---|---|
plex | media_server | 𝑥 ≤ 0.9.9.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References