CVE
- Id
- 13294
- CVE No.
- CVE-2005-2088
- Status
- Candidate
- Description
- The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
- Phase
- Assigned (20050630)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
95841 | 13294 | CVE-2005-2088 | BUGTRAQ:20050606 A new whitepaper by Watchfire - HTTP Request Smuggling | View |
95842 | 13294 | CVE-2005-2088 | URL:http://seclists.org/lists/bugtraq/2005/Jun/0025.html | View |
95843 | 13294 | CVE-2005-2088 | MISC:http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf | View |
95844 | 13294 | CVE-2005-2088 | MISC:http://www.securiteam.com/securityreviews/5GP0220G0U.html | View |
95845 | 13294 | CVE-2005-2088 | MLIST:[apache-httpd-announce] 20051014 Apache HTTP Server 2.0.55 Released | View |
95846 | 13294 | CVE-2005-2088 | URL:http://marc.info/?l=apache-httpd-announce&m=112931556417329&w=3 | View |
95847 | 13294 | CVE-2005-2088 | CONFIRM:http://www.apache.org/dist/httpd/CHANGES_1.3 | View |
95848 | 13294 | CVE-2005-2088 | CONFIRM:http://www.apache.org/dist/httpd/CHANGES_2.0 | View |
95849 | 13294 | CVE-2005-2088 | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm | View |
95850 | 13294 | CVE-2005-2088 | CONFIRM:https://secure-support.novell.com/KanisaPlatform/Publishing/741/3222109_f.SAL_Public.html | View |
95851 | 13294 | CVE-2005-2088 | AIXAPAR:PK13959 | View |
95852 | 13294 | CVE-2005-2088 | URL:http://www-1.ibm.com/support/search.wss?rs=0&q=PK13959&apar=only | View |
95853 | 13294 | CVE-2005-2088 | AIXAPAR:PK16139 | View |
95854 | 13294 | CVE-2005-2088 | URL:http://www-1.ibm.com/support/search.wss?rs=0&q=PK16139&apar=only | View |
95855 | 13294 | CVE-2005-2088 | APPLE:APPLE-SA-2005-11-29 | View |
95856 | 13294 | CVE-2005-2088 | URL:http://docs.info.apple.com/article.html?artnum=302847 | View |
95857 | 13294 | CVE-2005-2088 | DEBIAN:DSA-803 | View |
95858 | 13294 | CVE-2005-2088 | URL:http://www.debian.org/security/2005/dsa-803 | View |
95859 | 13294 | CVE-2005-2088 | DEBIAN:DSA-805 | View |
95860 | 13294 | CVE-2005-2088 | URL:http://www.debian.org/security/2005/dsa-805 | View |
95861 | 13294 | CVE-2005-2088 | HP:HPSBUX02074 | View |
95862 | 13294 | CVE-2005-2088 | URL:http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded | View |
95863 | 13294 | CVE-2005-2088 | HP:SSRT051251 | View |
95864 | 13294 | CVE-2005-2088 | URL:http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded | View |
95865 | 13294 | CVE-2005-2088 | HP:HPSBUX02101 | View |
95866 | 13294 | CVE-2005-2088 | URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00612828 | View |
95867 | 13294 | CVE-2005-2088 | HP:SSRT051128 | View |
95868 | 13294 | CVE-2005-2088 | URL:http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00612828 | View |
95869 | 13294 | CVE-2005-2088 | MANDRIVA:MDKSA-2005:130 | View |
95870 | 13294 | CVE-2005-2088 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:130 | View |
95871 | 13294 | CVE-2005-2088 | REDHAT:RHSA-2005:582 | View |
95872 | 13294 | CVE-2005-2088 | URL:http://www.redhat.com/support/errata/RHSA-2005-582.html | View |
95873 | 13294 | CVE-2005-2088 | SLACKWARE:SSA:2005-310-04 | View |
95874 | 13294 | CVE-2005-2088 | URL:http://slackware.com/security/viewer.php?l=slackware-security&y=2005&m=slackware-security.600000 | View |
95875 | 13294 | CVE-2005-2088 | SUNALERT:102197 | View |
95876 | 13294 | CVE-2005-2088 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-102197-1 | View |
95877 | 13294 | CVE-2005-2088 | SUNALERT:102198 | View |
95878 | 13294 | CVE-2005-2088 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1 | View |
95879 | 13294 | CVE-2005-2088 | SUSE:SUSE-SA:2005:046 | View |
95880 | 13294 | CVE-2005-2088 | URL:http://www.novell.com/linux/security/advisories/2005_46_apache.html | View |
95881 | 13294 | CVE-2005-2088 | SUSE:SUSE-SR:2005:018 | View |
95882 | 13294 | CVE-2005-2088 | URL:http://www.novell.com/linux/security/advisories/2005_18_sr.html | View |
95883 | 13294 | CVE-2005-2088 | TRUSTIX:TSLSA-2005-0059 | View |
95884 | 13294 | CVE-2005-2088 | URL:http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html | View |
95885 | 13294 | CVE-2005-2088 | UBUNTU:USN-160-2 | View |
95886 | 13294 | CVE-2005-2088 | URL:http://www.ubuntu.com/usn/usn-160-2 | View |
95887 | 13294 | CVE-2005-2088 | BID:14106 | View |
95888 | 13294 | CVE-2005-2088 | URL:http://www.securityfocus.com/bid/14106 | View |
95889 | 13294 | CVE-2005-2088 | BID:15647 | View |
95890 | 13294 | CVE-2005-2088 | URL:http://www.securityfocus.com/bid/15647 | View |
95891 | 13294 | CVE-2005-2088 | OVAL:oval:org.mitre.oval:def:11452 | View |
95892 | 13294 | CVE-2005-2088 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11452 | View |
95893 | 13294 | CVE-2005-2088 | VUPEN:ADV-2005-2140 | View |
95894 | 13294 | CVE-2005-2088 | URL:http://www.vupen.com/english/advisories/2005/2140 | View |
95895 | 13294 | CVE-2005-2088 | VUPEN:ADV-2005-2659 | View |
95896 | 13294 | CVE-2005-2088 | URL:http://www.vupen.com/english/advisories/2005/2659 | View |
95897 | 13294 | CVE-2005-2088 | VUPEN:ADV-2006-0789 | View |
95898 | 13294 | CVE-2005-2088 | URL:http://www.vupen.com/english/advisories/2006/0789 | View |
95899 | 13294 | CVE-2005-2088 | VUPEN:ADV-2006-1018 | View |
95900 | 13294 | CVE-2005-2088 | URL:http://www.vupen.com/english/advisories/2006/1018 | View |
95901 | 13294 | CVE-2005-2088 | VUPEN:ADV-2006-4680 | View |
95902 | 13294 | CVE-2005-2088 | URL:http://www.vupen.com/english/advisories/2006/4680 | View |
95903 | 13294 | CVE-2005-2088 | OVAL:oval:org.mitre.oval:def:840 | View |
95904 | 13294 | CVE-2005-2088 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:840 | View |
95905 | 13294 | CVE-2005-2088 | OVAL:oval:org.mitre.oval:def:1526 | View |
95906 | 13294 | CVE-2005-2088 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1526 | View |
95907 | 13294 | CVE-2005-2088 | OVAL:oval:org.mitre.oval:def:1629 | View |
95908 | 13294 | CVE-2005-2088 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1629 | View |
95909 | 13294 | CVE-2005-2088 | OVAL:oval:org.mitre.oval:def:1237 | View |
95910 | 13294 | CVE-2005-2088 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1237 | View |
95911 | 13294 | CVE-2005-2088 | SECTRACK:1014323 | View |
95912 | 13294 | CVE-2005-2088 | URL:http://securitytracker.com/id?1014323 | View |
95913 | 13294 | CVE-2005-2088 | SECUNIA:17813 | View |
95914 | 13294 | CVE-2005-2088 | URL:http://secunia.com/advisories/17813 | View |
95915 | 13294 | CVE-2005-2088 | SECUNIA:14530 | View |
95916 | 13294 | CVE-2005-2088 | URL:http://secunia.com/advisories/14530 | View |
95917 | 13294 | CVE-2005-2088 | SECUNIA:17487 | View |
95918 | 13294 | CVE-2005-2088 | URL:http://secunia.com/advisories/17487 | View |
95919 | 13294 | CVE-2005-2088 | SECUNIA:19072 | View |
95920 | 13294 | CVE-2005-2088 | URL:http://secunia.com/advisories/19072 | View |
95921 | 13294 | CVE-2005-2088 | SECUNIA:19073 | View |
95922 | 13294 | CVE-2005-2088 | URL:http://secunia.com/advisories/19073 | View |
95923 | 13294 | CVE-2005-2088 | SECUNIA:19317 | View |
95924 | 13294 | CVE-2005-2088 | URL:http://secunia.com/advisories/19317 | View |
95925 | 13294 | CVE-2005-2088 | SECUNIA:17319 | View |
95926 | 13294 | CVE-2005-2088 | URL:http://secunia.com/advisories/17319 | View |
95927 | 13294 | CVE-2005-2088 | SECUNIA:19185 | View |
95928 | 13294 | CVE-2005-2088 | URL:http://secunia.com/advisories/19185 | View |
95929 | 13294 | CVE-2005-2088 | SECUNIA:23074 | View |
95930 | 13294 | CVE-2005-2088 | URL:http://secunia.com/advisories/23074 | View |
95931 | 13294 | CVE-2005-2088 | SREASON:604 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
62626 | JVNDB-2005-000866 | Apache Tomcat における HTTP Request Smuggling の脆弱性 | Apache Tomcat には、複数の Content-Length ヘッダを含む HTTP リクエストの処理に不備が存在するため、不正な HTTP リクエストを処理することで HTTP Request Smuggling 攻撃を受ける脆弱性が存在します。 | CVE-2005-2090 | 13294 | 4.3 | http://jvndb.jvn.jp/ja/contents/2005/JVNDB-2005-000866.html | View |