CVE-2005-3751: XSS
HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3751?
CVE-2005-3751 is considered a high severity vulnerability due to its potential to allow remote attackers to exploit web caches and bypass firewalls.
How do I fix CVE-2005-3751?
To fix CVE-2005-3751, upgrade Pound to version 1.9.4 or later which addresses this vulnerability.
What attacks can be performed using CVE-2005-3751?
Attackers can use CVE-2005-3751 to poison web caches, bypass web application firewalls, and conduct cross-site scripting (XSS) attacks.
Which versions of Pound are affected by CVE-2005-3751?
Pound versions prior to 1.9.4, specifically up to version 1.9.3, are affected by CVE-2005-3751.
Who can be targeted by CVE-2005-3751?
CVE-2005-3751 can target any web service using affected versions of Pound, potentially affecting users and services relying on web caching.