7.5

CVE-2005-4827

Exploit

Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method name), which is supported by some proxy servers that convert tabs to spaces.  NOTE: this issue can be leveraged to conduct referer spoofing, HTTP Request Smuggling, and other attacks.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftIe Version6 Editionmicrosoft_windows_server_2003_sp1
MicrosoftIe Version6 Editionwindows_2000
MicrosoftIe Version6 Editionwindows_server_2003
MicrosoftIe Version6 Editionwindows_xp_professional_64bit
MicrosoftIe Version6 Updatesp1 Editionwindows_98
MicrosoftIe Version6 Updatesp1 Editionwindows_98_se
MicrosoftIe Version6 Updatesp1 Editionwindows_millennium
MicrosoftIe Version6 Updatesp1 Editionwindows_xpsp1
MicrosoftIe Version6 Updatewindows_2000_sp4
MicrosoftIe Version6 Updatewindows_server_2003_sp1
MicrosoftIe Version6 Updatewindows_server_2003_sp1_itanium
MicrosoftIe Version6 Updatewindows_server_2003_sp1_itanium_systems
MicrosoftIe Version6 Updatewindows_xp_sp2
MicrosoftIe Version6.0 Editionwindows_server
MicrosoftIe Version6.0 Editionwindows_server_2003
MicrosoftIe Version6.0 Editionwindowsxp
MicrosoftIe Version6.0 Updatesp1
MicrosoftIe Version6.0 Updatesp1 Editionwindows_2000
MicrosoftIe Version6.0 Updatesp1 Editionwindows_xp
MicrosoftIe Version6.0 Updatesp2
MicrosoftIe Version6.0 Updatesp2 Editionwindows_xp
MicrosoftIe Version6.0 Updatewindows_xp_sp2
MicrosoftInternet Explorer Version6 Updatesp1
MicrosoftInternet Explorer Version6.0
MicrosoftInternet Explorer Version6.0.2600
MicrosoftInternet Explorer Version6.0.2800
MicrosoftInternet Explorer Version6.0.2800.1106
MicrosoftInternet Explorer Version6.0.2900.2180
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 19.03% 0.951
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P