>> Microsoft Internet Explorer Request Splitting and Smuggling Vulnerabilities
Title : Microsoft Internet Explorer Request Splitting and Smuggling Vulnerabilities VUPEN ID : VUPEN/ADV-2008-0980 CVE ID : CVE-2008-1544 - CVE-2008-1545
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-25
Technical Description
Multiple vulnerabilities have been identified in Microsoft Internet Explorer, which could be exploited by malicious web sites to bypass security restrictions and gain knowledge of sensitive information. These issues are caused by input validation errors when handling "setRequestHeader()" requests, which could be exploited to manipulate the "Transfer Encoding", "Content-Length", "Host" and "Referer" headers and conduct HTTP request splitting and smuggling attacks.