HTTP: HTTP_PROXY Traffic Redirection
This signature detects attempts to exploit a known vulnerability against HTTP_PROXY environment variable using the Proxy HTTP header. Multiple products which includes PHP, Go, Apache HTTP Server, Apache Tomcat, HHVM, Lighttpd, Nginx and Python are vulnerable. Attackers can control proxy variable using this vulnerability which potentially leads to a man-in-the-middle attack.
Extended Description
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
Affected Products
Python python
References
CVE: CVE-2016-5387
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Python
Fedoraproject
Debian
6.8
5.8
5.1
5.0