CVE-2006-6276
published 2006-12-04CVE-2006-6276: HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web…
PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.61%
88.1th percentile
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified attack vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | java_system_application_server | — | — |
| sun | java_system_application_server | — | — |
| sun | java_system_web_proxy_server | — | — |
| sun | java_system_web_proxy_server | — | — |
| sun | java_system_web_server | — | — |
| sun | java_system_web_server | — | — |
| sun | one_application_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CAPEC
HTTP Request Smuggling
mitre_capec
[HIGH] HTTP Request Smuggling
CAPEC-33: HTTP Request Smuggling
An adversary abuses the flexibility and discrepancies in the parsing and interpretation of HTTP Request messages using various HTTP headers, request-line and body parameters as well as message sizes (denoted by the end of message signaled by a given HTTP header) by different intermediary HTTP agents (e.g., load balancer, reverse proxy, web caching proxies, application firewalls, etc.) to secretly send unauthorized and malicious HTTP requests to a back-end HTTP agent (e.g., web server). See CanPrecede relationships for possible consequences.
Alternate Terms: HTTP Desync
Execution Flow:
Step 1 [Explore]: [Survey network to identify target] The adversary performs network reconnaissance by monitoring relevant traffic to identify the network path and parsing
CWE
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
mitre_cwe
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent
(such as a proxy or firewall) in the data flow between two
entities such as a client and server, but it does not
interpret malformed HTTP requests or responses in ways that
are consistent with how the messages will be processed by
those entities that are at the ultimate destination.
HTTP requests or responses ("messages") can be
malformed or unexpected in ways that cause web servers or
clients to interpret the messages in different ways than
intermediary HTTP agents such as load balancers, reverse
proxies, web caching proxies, application firewalls,
etc. For example, an adversary may be able to add duplicate
or different header fields that a client or s
http://secunia.com/advisories/23186http://securitytracker.com/id?1017322http://securitytracker.com/id?1017323http://securitytracker.com/id?1017324http://sunsolve.sun.com/search/document.do?assetkey=1-26-102733-1http://www.securityfocus.com/bid/21371http://www.vupen.com/english/advisories/2006/4793https://exchange.xforce.ibmcloud.com/vulnerabilities/30662http://secunia.com/advisories/23186http://securitytracker.com/id?1017322http://securitytracker.com/id?1017323http://securitytracker.com/id?1017324http://sunsolve.sun.com/search/document.do?assetkey=1-26-102733-1http://www.securityfocus.com/bid/21371http://www.vupen.com/english/advisories/2006/4793https://exchange.xforce.ibmcloud.com/vulnerabilities/30662
2006-12-04
Published