CVE Database
/

CVE-2008-1545

Back to search

CVE-2008-1545

Published: Mar 28, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smuggling attacks via a POST containing a "Transfer-Encoding: chunked" header and a request body with an incorrect chunk size.

VendorProductVersions

n/a

n/a

affected
n/a

References

29453
third-party-advisory
x_refsource_SECUNIA
3786
third-party-advisory
x_refsource_SREASON
ADV-2008-0980
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now