Vulnerability Details CVE-2003-1286
HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server's administrative interface and external web servers, by making a "Connection: keep-alive" request before the proxy requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.098
EPSS Ranking 92.6%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2003-1286
-
cpe:2.3:a:sambar:sambar_server:5.0
-
cpe:2.3:a:sambar:sambar_server:5.1
-
cpe:2.3:a:sambar:sambar_server:5.2
-
cpe:2.3:a:sambar:sambar_server:5.3
-
cpe:2.3:a:sambar:sambar_server:6.0