Sploitus

CVE-2005-4874

No indexed exploits for CVE-2005-4874 yet

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.

Affected products
Mozilla Firefox
Mozilla
= 1.7.8
Fix
Available
CVSS 2.0
4.3 MEDIUM
EPSS
1.2% (66th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2008-03-28
CVE-2005-4874 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2005-4874 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2005-4874 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.