CVE-2007-5034
Last modified
CVE-2007-5034 is a vulnerability of currently unknown severity. ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. NOTE: this issue only occurs when a proxy is defined for https.. EPSS estimates a 2.60% chance of exploitation in the next 30 days.
Description
ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. NOTE: this issue only occurs when a proxy is defined for https.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Elinks | Elinks | <= 0.11.1 |
| Elinks | Elinks | <= 0.11.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5034?
How severe is CVE-2007-5034?
How do I fix CVE-2007-5034?
Are you affected by CVE-2007-5034?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
