Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2004-0189

The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.051
EPSS Ranking 89.3%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2004-0189
  • Squid » Squid » Version: 2.0_patch2
    cpe:2.3:a:squid:squid:2.0_patch2
  • Squid » Squid » Version: 2.1_patch2
    cpe:2.3:a:squid:squid:2.1_patch2
  • Squid » Squid » Version: 2.3_stable5
    cpe:2.3:a:squid:squid:2.3_stable5
  • Squid » Squid » Version: 2.4
    cpe:2.3:a:squid:squid:2.4
  • Squid » Squid » Version: 2.4_stable7
    cpe:2.3:a:squid:squid:2.4_stable7
  • Squid » Squid » Version: 2.5_stable3
    cpe:2.3:a:squid:squid:2.5_stable3
  • Squid » Squid » Version: 2.5_stable4
    cpe:2.3:a:squid:squid:2.5_stable4


Contact Us

Shodan ® - All rights reserved