Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-1545 (Internet Explorer)

BugsAlert Home > CVE-2008-1545 (Internet Explorer)
 
 

The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smuggling attacks via a POST containing a "Transfer-Encoding: chunked" header and a request body with an incorrect chunk size.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1545

Learn more about CVE-2008-1545 (Internet Explorer)
 
Tags: cve-2008-1545 internet explorer

Related Items

      CVE-2008-2853 (easy_webstore)

      FrSIRT - Borland StarTeam MPX Integer and Heap Overflow Vulnerabilities

      Fedora update for krb5

      FrSIRT - Mandriva Security Update Fixes Joomla Multiple Remote Vulnerabilities

      CVE-2008-2533 (phoenix_view_cms)

      Brief: Weakness in Debian undermines crypto

      Don't get hacked off at the Olympic Games - Sophos issues top security tips for

 

Pixel