CGI Namespace Conflict Man-In-The-Middle (httpoxy; CVE-2016-5385; CVE-2016-5386; CVE-2016-5387; CVE-2016-5388; CVE-2016-1000109; CVE-2016-1000110)

Namespace conflict related to HTTP proxy headers allows an attacker to configure the HTTP_PROXY environment variable. A successful exploitation might allow an attacker to launch a man-in-the-middle attack and redirect traffic to an arbitrary host.

Leave a Reply