lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <CAJ9badm=zn_BoycbsnLwkgpj4MTbOaaQGmT_GoDo80SoMEBBrQ@mail.gmail.com> Date: Mon, 9 Jan 2017 19:23:19 +0000 From: Celso Bento <celsobento2009@...il.com> To: fulldisclosure@...lists.org Subject: [FD] Hotlinking Vulnerability in PHProxy 0.5b2 A flaw exists in PHProxy 0.5b2 hotlinking feature which allow anyone using some coding to link to proxified pages. By default hotlinking is active to prevent users from retrieving pages directly from the proxy requiring them to use the form. This can be easily bypassed. This is the same type of vulnerability found on Glype 1.4.4. Other webproxies may be vulnerable too... _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/