7.5
CVSSv2

CVE-2005-4827

Published: 31/12/2005 Updated: 23/07/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Internet Explorer 6.0, and possibly other versions, allows remote malicious users to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method name), which is supported by some proxy servers that convert tabs to spaces. NOTE: this issue can be leveraged to conduct referer spoofing, HTTP Request Smuggling, and other attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet explorer 6.0

microsoft internet explorer 6.0.2600

microsoft internet explorer 6.0.2800

microsoft ie 6

microsoft internet explorer 6.0.2900.2180

microsoft ie 6.0

microsoft internet explorer 6

microsoft internet explorer 6.0.2800.1106

canon network camera server vb101