Description
Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.
Remediation
References
Related Vulnerabilities
WordPress Plugin Bulk Datetime Change Security Bypass (1.11)
Zope Web Application Server Other Vulnerability (CVE-2002-0688)
WordPress Plugin ACF:Better Search Cross-Site Request Forgery (3.3.0)
WordPress Plugin SP Project & Document Manager Cross-Site Scripting (4.25)
WordPress Plugin Arigato Autoresponder and Newsletter Multiple Unspecified Vulnerabilities (2.4.2)