VulnerabilityModified
CVE-2005-3751
HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers.
MEDIUM 4.3EPSS 1.47%
Does this matter?
Lower severity and a low EPSS score (1.47%). Track it; it rarely justifies an emergency change on its own.
Description
HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.47% probability · 72th percentile
- CISA KEV
- Not listed
- Affected
- apsis/pound
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/18367Vendor Advisory
- http://secunia.com/advisories/18381Vendor Advisory
- http://secunia.com/advisories/20215Vendor Advisory
- http://secunia.com/advisories/20510Vendor Advisory
- http://www.apsis.ch/pound/pound_list/archive/2005/2005-10/1129827166000/index_html?fullMode=1#1129827166000
- http://www.debian.org/security/2005/dsa-934
- http://www.gentoo.org/security/en/glsa/glsa-200606-05.xml
- http://www.novell.com/linux/security/advisories/2006_05_19.html
- http://secunia.com/advisories/18367Vendor Advisory
- http://secunia.com/advisories/18381Vendor Advisory
- http://secunia.com/advisories/20215Vendor Advisory
- http://secunia.com/advisories/20510Vendor Advisory
- http://www.apsis.ch/pound/pound_list/archive/2005/2005-10/1129827166000/index_html?fullMode=1#1129827166000
- http://www.debian.org/security/2005/dsa-934
- http://www.gentoo.org/security/en/glsa/glsa-200606-05.xml
- http://www.novell.com/linux/security/advisories/2006_05_19.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.