CVE-2005-4827
Gravedad CVSS v2.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
31/12/2005
Última modificación:
03/04/2025
Descripción
*** Pendiente de traducción *** Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method name), which is supported by some proxy servers that convert tabs to spaces. NOTE: this issue can be leveraged to conduct referer spoofing, HTTP Request Smuggling, and other attacks.
Impacto
Puntuación base 2.0
7.50
Gravedad 2.0
ALTA
Productos y versiones vulnerables
CPE | Desde | Hasta |
---|---|---|
cpe:2.3:a:microsoft:ie:6:*:microsoft_windows_server_2003_sp1:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:*:windows_2000:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:*:windows_server_2003:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:*:windows_xp_professional_64bit:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:sp1:windows_98:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:sp1:windows_98_se:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:sp1:windows_millennium:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:sp1:windows_xpsp1:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:windows_2000_sp4:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1_itanium:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1_itanium_systems:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:windows_xp_sp2:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6.0:*:windows_server:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6.0:*:windows_server_2003:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- http://seclists.org/fulldisclosure/2007/Feb/0081.html
- http://www.securityfocus.com/archive/1/411585
- http://www.securityfocus.com/archive/1/459172/100/0/threaded
- http://www.securityfocus.com/archive/1/459172/100/0/threaded
- http://www.securityfocus.com/bid/14969
- http://seclists.org/fulldisclosure/2007/Feb/0081.html
- http://www.securityfocus.com/archive/1/411585
- http://www.securityfocus.com/archive/1/459172/100/0/threaded
- http://www.securityfocus.com/archive/1/459172/100/0/threaded
- http://www.securityfocus.com/bid/14969