CVE-2005-4874 Information

Description

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method which allows remote attackers to obtain (1) proxy authentication passwords via a request with a \Max-Forwards: 0\ header or (2) arbitrary local passwords on the web server that hosts this object.

Reference

https://bugzilla.mozilla.org/show_bug.cgi?id=297078 https://bugzilla.mozilla.org/show_bug.cgi?id=302489 https://exchange.xforce.ibmcloud.com/vulnerabilities/41553

Share on: