CVE-2003-1286
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 3.4%
from disclosure to weapon0 days
Published on NVDNov 22
1st PoCJan 30
exploitation probability
3.4%top 12% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server's administrative interface and external web servers, by making a "Connection: keep-alive" request before the proxy requests.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/24076⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/bugtraq/2004-04/0353.htmlhttp://secunia.com/advisories/9578http://securitytracker.com/id?1007819https://exchange.xforce.ibmcloud.com/vulnerabilities/16054http://www.idefense.com/application/poi/display?id=103&type=vulnerabilities&flashstatus=truehttp://www.sambar.com/security.htmhttp://www.securityfocus.com/bid/10256