CVE-2005-4874
Last modified
CVE-2005-4874 is a vulnerability of currently unknown severity. The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.. EPSS estimates a 1.25% chance of exploitation in the next 30 days.
Description
The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Mozilla | 1.7.8 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=302489Exploit, Patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=302489Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-4874?
How severe is CVE-2005-4874?
How do I fix CVE-2005-4874?
Are you affected by CVE-2005-4874?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
