CVE-2005-2729 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 6.6% (pctl 94)
Patch early
A public exploit exists.
Description
The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote attackers to bypass firewall rules and connect to local services.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 6.56% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-08-30 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| astaro | security linux |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Astaro Security Linux 6.0 01 - HTTP CONNECT Unauthorized Access | 2005-08-25 |
References
- http://marc.info/?l=bugtraq&m=112501186602731&w=2
- http://secunia.com/advisories/16578/
- http://www.securityfocus.com/bid/14665
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22021
- http://marc.info/?l=bugtraq&m=112501186602731&w=2
- http://secunia.com/advisories/16578/
- http://www.securityfocus.com/bid/14665
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22021
→ the Explorer · watch your stack · NVD