CVE-2008-1544: Input Validation
The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 5.01, 6, and 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers to (1) conduct HTTP request splitting and HTTP request smuggling attacks via an incorrect Content-Length header, (2) access arbitrary virtual hosts via a modified Host header, (3) bypass referrer restrictions via an incorrect Referer header, and (4) bypass the same-origin policy and obtain sensitive information via a crafted request header.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1544?
CVE-2008-1544 is classified as a medium severity vulnerability due to its potential for HTTP request splitting and header injection.
How do I fix CVE-2008-1544?
To mitigate CVE-2008-1544, update Microsoft Internet Explorer to the latest version or apply any available security patches.
Which versions of Internet Explorer are affected by CVE-2008-1544?
CVE-2008-1544 affects Microsoft Internet Explorer 5.01, 6, and 7.
What type of attack can CVE-2008-1544 lead to?
CVE-2008-1544 can lead to HTTP request splitting, which may allow attackers to execute further malicious actions.
Are any operating systems vulnerable to CVE-2008-1544?
Yes, Microsoft Windows 2000, Windows Server 2003, and Windows XP are among the operating systems that could be affected when used with vulnerable versions of Internet Explorer.