Friday, July 08, 2005
Apache Request Smuggling Vulnerability Found
"Whitedust is reporting on a HTTP request smuggling vulnerability in Apache. The flaw apparently allows attackers to piggy back valid HTTP requests over the 'Content-Length:' header, which can result in cache poisoning, cross-site scripting, session hijacking and other various kinds of attack. This flaw affects most of the 2.0.x branch of Apache's HTTPD server."
source: http://it.slashdot.org/article.pl?sid=05/07/08/0453212&tid=172&tid=128&tid=2
source: http://it.slashdot.org/article.pl?sid=05/07/08/0453212&tid=172&tid=128&tid=2