CVE-2005-4874
Last modified
CVE-2005-4874 is a vulnerability of currently unknown severity. The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.. EPSS estimates a 1.25% chance of exploitation in the next 30 days.
Description
The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Mozilla | 1.7.8 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=302489Exploit, Patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=302489Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-4874?
How severe is CVE-2005-4874?
How do I fix CVE-2005-4874?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-4868Shared memory sections and events in IBM DB2 8.1 have defaul…7.1
- CVE-2005-4869The (1) to_char and (2) to_date function in IBM DB2 8.1 allo…
- CVE-2005-4870Stack-based buffer overflows in the (1) xmlvarcharfromfile, …
- CVE-2005-4871Certain XML functions in IBM DB2 8.1 run with the privileges…
- CVE-2005-4872Perl-Compatible Regular Expression (PCRE) library before 6.2…
- CVE-2005-4873Multiple stack-based buffer overflows in the phpcups PHP mod…
- CVE-2005-4875TYPO3 3.8.0 and earlier allows remote attackers to obtain se…
- CVE-2005-4876Cross-site scripting (XSS) vulnerability in the login form (…
- CVE-2005-4877Cross-site scripting (XSS) vulnerability in the login form (…
- CVE-2005-4878Multiple cross-site scripting (XSS) vulnerabilities in (1) a…
- CVE-2005-4879Multiple cross-site scripting (XSS) vulnerabilities in jax_g…
- CVE-2005-4880Jax Guestbook 3.1 and 3.31 stores sensitive information unde…
Are you affected by CVE-2005-4874?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
