Heap
31-03-08, 16:22
The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers to (1) conduct HTTP request splitting and HTTP request smuggling attacks via an incorrect Content-Length header, (2) access arbitrary virtual hosts via a modified Host header, and (3) bypass referrer restrictions via an incorrect Referer header.
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1544)
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1544)