vendor:
Glype
by:
Securify
7,5
CVSS
HIGH
Local Address Filter Bypass
200
CWE
Product Name: Glype
Affected Version From: Glype 1.4.9
Affected Version To: Glype 1.4.9
Patch Exists: YES
Related CWE: N/A
CPE: a:glype:glype:1.4.9
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014
Glype proxy local address filter bypass
A vulnerability has been identified in the Glype web-based proxy. Glype has a filter to disallow users from surfing to local addresses, to prevents users from attacking the local server/network Glype is running on. The filter can easily be bypassed by using IPs in decimal form.
Mitigation:
Glype was informed and a fixed version (1.4.10) is now available at www.glype.com