|
|
Info |
Last Modified |
| 5 months ago |
|
|
|
|
|
This Entry needs help! It is only 10% Complete. Click the edit link above to add more information.
Contributing is fast and easy, and benefits the entire security community.
|
Keywords |
c01482941,HPSBST02344,SSRT080087
|
|
Description |
(Description Provided by CVE) : The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 5.01, 6, and 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers to (1) conduct HTTP request splitting and HTTP request smuggling attacks via an incorrect Content-Length header, (2) access arbitrary virtual hosts via a modified Host header, (3) bypass referrer restrictions via an incorrect Referer header, and (4) bypass the same-origin policy and obtain sensitive information via a crafted request header.
|
|
Classification |
Solution:
Patch
Disclosure:
Vendor Verified
|
|
Products |
Unknown or Incomplete
|
|
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|