CVE-2006-6982
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/02/2007
Last modified:
09/04/2025
Description
3proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic authentication, which might cause browsers with incomplete RFC2616/RFC2617 support to use basic cleartext authentication even if NTLM is available, which makes it easier for attackers to steal credentials.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:3proxy:3proxy:0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:3proxy:3proxy:0.5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:3proxy:3proxy:0.5.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



