CVE-2005-0316 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 8.2% (pctl 95)
Patch early
A public exploit exists.
Description
WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 8.23% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-01-28 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| webwasher | webwasher classic |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WebWasher Classic 2.2/2.3 - HTTP CONNECT Unauthorized Access | 2005-01-28 |
References
- http://marc.info/?l=bugtraq&m=110693045507245&w=2
- http://secunia.com/advisories/14058
- http://securitytracker.com/id?1013036
- http://www.oliverkarow.de/research/WebWasherCONNECT.txt
- http://www.securityfocus.com/bid/12394
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19144
- http://marc.info/?l=bugtraq&m=110693045507245&w=2
- http://secunia.com/advisories/14058
- http://securitytracker.com/id?1013036
- http://www.oliverkarow.de/research/WebWasherCONNECT.txt
- http://www.securityfocus.com/bid/12394
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19144
→ the Explorer · watch your stack · NVD