CVE-1999-1273
CVSS 2.0 Score 7.5 of 10 (high)
Details
Published Feb 20, 1998
Updated: Nov 20, 2024
Summary
CVE-1999-1273 is a vulnerability affecting Squid Internet Object Cache version 1.1.20. This issue permits users to bypass access control lists (ACLs) by encoding URLs with hexadecimal escape sequences. An attacker could potentially gain unauthorized access to restricted content, leading to security breaches and unintended data exposure. The vulnerability can be mitigated by upgrading to a patched version or implementing specific configuration changes to restrict the use of hexadecimal escape sequences.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Squid Software
Affected Vendors
- Squid Software Foundation