CVE-2008-1545 (Internet Explorer) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2008-1545 (Internet Explorer)


Heap
31-03-08, 16:22
The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smuggling attacks via a POST containing a "Transfer-Encoding: chunked" header and a request body with an incorrect chunk size.

More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1545)