Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8m8j-89c8-3vh7

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.

EPSS

Процентиль: 46%
0.00227
Низкий

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 19 лет назад

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.

nvd
больше 19 лет назад

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.

debian
больше 19 лет назад

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE met ...

EPSS

Процентиль: 46%
0.00227
Низкий

Дефекты

CWE-94