CacheFlow CacheOS HTTP CONNECT TCP Tunnel Vulnerability
BID:4143
Info
CacheFlow CacheOS HTTP CONNECT TCP Tunnel Vulnerability
| Bugtraq ID: | 4143 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2002 12:00AM |
| Updated: | Feb 20 2002 12:00AM |
| Credit: | Reported by Steve VanDevender <[email protected]>. |
| Vulnerable: |
CacheFlow CacheOS 4.0.14 CacheFlow CacheOS 4.0.13 CacheFlow CacheOS 4.0.12 CacheFlow CacheOS 4.0.11 CacheFlow CacheOS 4.0 CacheFlow CacheOS 3.1.21 CacheFlow CacheOS 3.1.19 CacheFlow CacheOS 3.1.18 CacheFlow CacheOS 3.1.17 CacheFlow CacheOS 3.1.16 CacheFlow CacheOS 3.1.15 CacheFlow CacheOS 3.1.14 CacheFlow CacheOS 3.1.13 CacheFlow CacheOS 3.1.12 CacheFlow CacheOS 3.1.11 CacheFlow CacheOS 3.1 .20 CacheFlow CacheOS 3.1 .10 CacheFlow CacheOS 3.1 .09 CacheFlow CacheOS 3.1 .08 CacheFlow CacheOS 3.1 .07 CacheFlow CacheOS 3.1 .06 CacheFlow CacheOS 3.1 .05 CacheFlow CacheOS 3.1 .04 CacheFlow CacheOS 3.1 .03 CacheFlow CacheOS 3.1 .02 CacheFlow CacheOS 3.1 CacheFlow CacheOS |
| Not Vulnerable: |
CacheFlow CacheOS 5.0 |
Exploit / POC
CacheFlow CacheOS HTTP CONNECT TCP Tunnel Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
CacheFlow CacheOS HTTP CONNECT TCP Tunnel Vulnerability
Solution:
Version 5.0 of CacheOS disables CONNECT support for ports other than 443 by default.
Solution:
Version 5.0 of CacheOS disables CONNECT support for ports other than 443 by default.