Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-4553

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.859
EPSS Ranking 99.3%
CVSS Severity
CVSS v3 Score 8.6
CVSS v2 Score 5.0
References
Products affected by CVE-2016-4553


Contact Us

Shodan ® - All rights reserved