CVE-2009-2057

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
15/06/2009
Last modified:
09/04/2025

Description

Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:ie:5.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:5.0:sp4:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:5.22:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6.0:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:3.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:3.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:3.2:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.0.1:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.0.1:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.01:*:*:*:*:*:*:*