CVE-2008-1544 describes a vulnerability in the XMLHttpRequest object's setRequestHeader method in Microsoft Internet Explorer versions 5.01, 6, and 7, affecting various Windows operating systems. Attackers can bypass security restrictions by appending 8-bit character sequences to HTTP header names, enabling HTTP request splitting, smuggling, virtual host access, referrer restriction bypass, and same-origin policy circumvention to obtain sensitive information. This vulnerability has a CVSS score of 7.1, indicating high severity due to its network-based attack vector and high impact on confidentiality. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, suggesting awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.01CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:5.01:sp4:*:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.