CVE-1999-1273

CVSS 2.0 Score 7.5 of 10 (high)

Details

Published Feb 20, 1998
Updated: Nov 20, 2024

Summary

CVE-1999-1273 is a vulnerability affecting Squid Internet Object Cache version 1.1.20. This issue permits users to bypass access control lists (ACLs) by encoding URLs with hexadecimal escape sequences. An attacker could potentially gain unauthorized access to restricted content, leading to security breaches and unintended data exposure. The vulnerability can be mitigated by upgrading to a patched version or implementing specific configuration changes to restrict the use of hexadecimal escape sequences.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Squid Software

Affected Vendors

  • Squid Software Foundation