Title : HP Security Update Fixes VirtualVault Apache HTTP Request Smuggling Vulnerability VUPEN ID : VUPEN/ADV-2006-1018 CVE ID : CVE-2005-2088 CWE ID : CWE-OVAL1526 - CWE-OVAL1237
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-03-21
Technical Description
HP has released security patches to address a vulnerability identified in VirtualVault. This flaw is due to an error when handling HTTP requests containing both "Transfer-Encoding: chunked" and "Content-Length" headers, which could allow the bypass of Web application firewall protection or lead to cross site scripting attacks. For additional information, see : VUPEN/ADV-2005-2140