Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Internet Explorer XmlHttpRequest Parameter Validation Weakness

Microsoft Internet Explorer is prone to a weakness that permits the injection of arbitrary HTTP requests due to improper verification of parameters passed to XmlHttpRequest.

An attacker may craft a website that instantiates the affected control and forces the browser to request a site on the same host (or another host in case a forwarding proxy is employed). The attacker would then intercept the response and steal sensitive data to aid in further attacks.

A successful attack may have various consequences facilitating HTTP request smuggling, man-in-the-middle attacks, and information disclosure.







 

Privacy Statement
Copyright 2009, SecurityFocus