diff options
author | Daniel Stenberg <daniel@haxx.se> | 2003-08-02 23:36:35 +0000 |
---|---|---|
committer | Daniel Stenberg <daniel@haxx.se> | 2003-08-02 23:36:35 +0000 |
commit | db9f87f697c86cdeca4e6da9f8baabb8246b2d0e (patch) | |
tree | d2a5c5a2bfec0b802176f78ab85fd8df67512cdd /CHANGES | |
parent | 3270ea55dd6ace258eabbd64a873ccf328976e7a (diff) |
When proxy authentication is used in a CONNECT request (as used for all SSL
connects and otherwise enforced tunnel-thru-proxy requests), the same
authentication header is also wrongly sent to the remote host.
The name and password can then be captured by an evil host and possibly get
used for malicious purposes.
Diffstat (limited to 'CHANGES')
0 files changed, 0 insertions, 0 deletions