CVE-2005-2703: Code Injection
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2703?
CVE-2005-2703 is considered a moderate to high severity vulnerability due to the potential for HTTP request smuggling and splitting attacks.
How do I fix CVE-2005-2703?
To fix CVE-2005-2703, upgrade to Mozilla Firefox version 1.0.7 or later, or Mozilla Suite version 1.7.12 or later.
What types of software are affected by CVE-2005-2703?
CVE-2005-2703 affects Mozilla Firefox versions prior to 1.0.7 and Mozilla Suite versions prior to 1.7.12.
What can an attacker do with CVE-2005-2703?
An attacker can exploit CVE-2005-2703 to modify HTTP headers of XMLHttpRequests made by the client, potentially leading to further attacks on servers or proxies.
When was CVE-2005-2703 reported?
CVE-2005-2703 was reported in 2005 as a vulnerability affecting certain versions of Firefox and Mozilla Suite.