UltraVNC Repeater before 1300 does not restrict destination IP addresses or TCP ports, which allows remote attackers to obtain open-proxy functionality by using a :: substring in between the IP address and port number.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/BLUU-A9WQVP | third party advisory us government resource |
http://www.kb.cert.org/vuls/id/735416 | third party advisory us government resource |
http://www.securityfocus.com/bid/92348 | vdb entry |