Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-5384
Description:Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more information than would be sent to the proxy itself in the case of HTTPS. Normally the Proxy Auto-Config file is specified by the user or machine owner and presumed to be non-malicious, but if a user has enabled Web Proxy Auto Detect (WPAD) this file can be served remotely. This vulnerability affects Firefox < 51.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-5384
BugTraq ID: 95763
http://www.securityfocus.com/bid/95763
https://www.contextis.com//resources/blog/leaking-https-urls-20-year-old-vulnerability/
http://www.securitytracker.com/id/1037693




© 1998-2025 E-Soft Inc. All rights reserved.