7.5

CVE-2005-4827

Exploit
Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method name), which is supported by some proxy servers that convert tabs to spaces.  NOTE: this issue can be leveraged to conduct referer spoofing, HTTP Request Smuggling, and other attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Ie Version 6 Edition microsoft_windows_server_2003_sp1
Microsoft ≫ Ie Version 6 Edition windows_2000
Microsoft ≫ Ie Version 6 Edition windows_server_2003
Microsoft ≫ Ie Version 6 Edition windows_xp_professional_64bit
Microsoft ≫ Ie Version 6 Update sp1 Edition windows_98
Microsoft ≫ Ie Version 6 Update sp1 Edition windows_98_se
Microsoft ≫ Ie Version 6 Update sp1 Edition windows_millennium
Microsoft ≫ Ie Version 6 Update sp1 Edition windows_xpsp1
Microsoft ≫ Ie Version 6 Update windows_2000_sp4
Microsoft ≫ Ie Version 6 Update windows_server_2003_sp1
Microsoft ≫ Ie Version 6 Update windows_server_2003_sp1_itanium
Microsoft ≫ Ie Version 6 Update windows_server_2003_sp1_itanium_systems
Microsoft ≫ Ie Version 6 Update windows_xp_sp2
Microsoft ≫ Ie Version 6.0 Edition windows_server
Microsoft ≫ Ie Version 6.0 Edition windows_server_2003
Microsoft ≫ Ie Version 6.0 Edition windowsxp
Microsoft ≫ Ie Version 6.0 Update sp1
Microsoft ≫ Ie Version 6.0 Update sp1 Edition windows_2000
Microsoft ≫ Ie Version 6.0 Update sp1 Edition windows_xp
Microsoft ≫ Ie Version 6.0 Update sp2
Microsoft ≫ Ie Version 6.0 Update sp2 Edition windows_xp
Microsoft ≫ Ie Version 6.0 Update windows_xp_sp2
Microsoft ≫ Internet Explorer Version 6 Update sp1
Microsoft ≫ Internet Explorer Version 6.0
Microsoft ≫ Internet Explorer Version 6.0.2600
Microsoft ≫ Internet Explorer Version 6.0.2800
Microsoft ≫ Internet Explorer Version 6.0.2800.1106
Microsoft ≫ Internet Explorer Version 6.0.2900.2180
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.67% 0.953
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://seclists.org/fulldisclosure/2007/Feb/0081.html
Vendor Advisory
http://www.securityfocus.com/archive/1/411585
Exploit
http://www.securityfocus.com/archive/1/459172/100/0/threaded
http://www.securityfocus.com/bid/14969