Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/48681 | vdb entry |
http://secunia.com/advisories/33891 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/33687 | vdb entry |
http://www.securitytracker.com/id?1021716 | vdb entry |
http://www.securityfocus.com/archive/1/500760/100/0/threaded | mailing list |