Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mqxg-27cj-85m3

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smuggling attacks via a POST containing a "Transfer-Encoding: chunked" header and a request body with an incorrect chunk size.

The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smuggling attacks via a POST containing a "Transfer-Encoding: chunked" header and a request body with an incorrect chunk size.

EPSS

Процентиль: 96%
0.24205
Средний

Дефекты

CWE-20

Связанные уязвимости

nvd
почти 18 лет назад

The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smuggling attacks via a POST containing a "Transfer-Encoding: chunked" header and a request body with an incorrect chunk size.

EPSS

Процентиль: 96%
0.24205
Средний

Дефекты

CWE-20