CVE-2008-1545
The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smuggling…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smuggling attacks via a POST containing a "Transfer-Encoding: chunked" header and a request body with an incorrect chunk size.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 11.84% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29453Vendor Advisory
- http://securityreason.com/securityalert/3786
- http://www.mindedsecurity.com/MSA01240108.htmlExploit
- http://www.securityfocus.com/archive/1/489960/100/0/threaded
- http://www.vupen.com/english/advisories/2008/0980
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42804
- http://secunia.com/advisories/29453Vendor Advisory
- http://securityreason.com/securityalert/3786
- http://www.mindedsecurity.com/MSA01240108.htmlExploit
- http://www.securityfocus.com/archive/1/489960/100/0/threaded
- http://www.vupen.com/english/advisories/2008/0980
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42804
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.