|
Microsoft Internet Explorer XmlHttpRequest Parameter Validation Weakness
Microsoft Internet Explorer is prone to a weakness that permits the injection of arbitrary HTTP requests due to improper verification of parameters passed to XmlHttpRequest. An attacker may craft a website that instantiates the affected control and forces the browser to request a site on the same host (or another host in case a forwarding proxy is employed). The attacker would then intercept the response and steal sensitive data to aid in further attacks. A successful attack may have various consequences facilitating HTTP request smuggling, man-in-the-middle attacks, and information disclosure. |
|
|
Privacy Statement |