Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.
References
Link Resource
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
http://secunia.com/advisories/16911 Vendor Advisory
http://secunia.com/advisories/16917 Vendor Advisory
http://secunia.com/advisories/16977 Vendor Advisory
http://secunia.com/advisories/17014 Vendor Advisory
http://secunia.com/advisories/17026 Vendor Advisory
http://secunia.com/advisories/17042 Vendor Advisory
http://secunia.com/advisories/17090 Vendor Advisory
http://secunia.com/advisories/17149 Vendor Advisory
http://secunia.com/advisories/17263 Vendor Advisory
http://secunia.com/advisories/17284 Vendor Advisory
http://securitytracker.com/id?1014954
http://www.debian.org/security/2005/dsa-838
http://www.debian.org/security/2005/dsa-866
http://www.debian.org/security/2005/dsa-868
http://www.mandriva.com/security/advisories?name=MDKSA-2005:169
http://www.mandriva.com/security/advisories?name=MDKSA-2005:170
http://www.mandriva.com/security/advisories?name=MDKSA-2005:174
http://www.mozilla.org/security/announce/mfsa2005-58.html
http://www.novell.com/linux/security/advisories/2005_58_mozilla.html
http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00004.html
http://www.redhat.com/support/errata/RHSA-2005-785.html
http://www.redhat.com/support/errata/RHSA-2005-789.html
http://www.redhat.com/support/errata/RHSA-2005-791.html
http://www.securityfocus.com/bid/14923
http://www.securityfocus.com/bid/15495
http://www.ubuntu.com/usn/usn-200-1
http://www.vupen.com/english/advisories/2005/1824
https://exchange.xforce.ibmcloud.com/vulnerabilities/22376
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10767
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1089
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2005-09-23T04:00:00

Updated: 2017-10-10T00:57:01

Reserved: 2005-08-26T00:00:00


Link: CVE-2005-2703

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2005-09-23T19:03:00.000

Modified: 2017-10-11T01:30:18.857


Link: CVE-2005-2703

JSON object: View

cve-icon Redhat Information

No data.

CWE