CVE-2012-2566 - Shivery Breakdowns
Description
Bloxx Web Filtering before 5.0.14 does not properly interpret X-Forwarded-For headers during access-control and logging operations for HTTPS connection attempts which allows remote attackers to bypass intended IP address and domain restrictions and trigger misleading log entries via a crafted header.
Reference
http://www.kb.cert.org/vuls/id/722963 http://www.kb.cert.org/vuls/id/MAPG-8R9LBY http://www.securityfocus.com/bid/53715