Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-4874

Опубликовано: 31 дек. 2005
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mozilla:mozilla:1.7.8:*:*:*:*:*:*:*

EPSS

Процентиль: 46%
0.00227
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 19 лет назад

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.

debian
больше 19 лет назад

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE met ...

github
больше 3 лет назад

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.

EPSS

Процентиль: 46%
0.00227
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-94