An attacker may be able to conduct cross-site scripting and other attacks against users who have these components enabled.
If a product does not neutralize user controlled data being placed in the header of an HTTP response coming from the server, the header may contain a script that will get executed in the client's browser context, potentially resulting in a cross site scripting vulnerability or possibly an HTTP response splitting attack. It is important to carefully control data that is being placed both in HTTP response header and in the HTTP response body to ensure that no scripting syntax is present, taking various encodings into account.
Scope | Impact | Likelihood |
---|---|---|
Integrity Confidentiality Availability | Execute Unauthorized Code or Commands Note: Run arbitrary code. | |
Confidentiality | Read Application Data Note: Attackers may be able to obtain sensitive information. |
References | Description |
---|---|
CVE-2006-3918 | Web server does not remove the Expect header from an HTTP request when it is reflected back in an error message, allowing a Flash SWF file to perform XSS attacks. |
Name | Organization | Date | Date release | Version |
---|---|---|---|---|
Evgeny Lebanidze | Cigital | Draft 8 |
Name | Organization | Date | Comment |
---|---|---|---|
Sean Eidemiller | Cigital | added/updated demonstrative examples | |
CWE Content Team | MITRE | updated Common_Consequences, Relationships, Observed_Example | |
CWE Content Team | MITRE | updated Description, Name, Observed_Examples, Relationships | |
CWE Content Team | MITRE | updated Relationships | |
CWE Content Team | MITRE | updated Description, Name | |
CWE Content Team | MITRE | updated Common_Consequences | |
CWE Content Team | MITRE | updated Description, Name | |
CWE Content Team | MITRE | updated Demonstrative_Examples, Description, Observed_Examples | |
CWE Content Team | MITRE | updated Common_Consequences | |
CWE Content Team | MITRE | updated Description | |
CWE Content Team | MITRE | updated Common_Consequences | |
CWE Content Team | MITRE | updated Relationships | |
CWE Content Team | MITRE | updated Potential_Mitigations | |
CWE Content Team | MITRE | updated Relationships, Taxonomy_Mappings | |
CWE Content Team | MITRE | updated Applicable_Platforms, Enabling_Factors_for_Exploitation | |
CWE Content Team | MITRE | updated Applicable_Platforms, Relationships | |
CWE Content Team | MITRE | updated Relationships | |
CWE Content Team | MITRE | updated Description | |
CWE Content Team | MITRE | updated Relationships, Time_of_Introduction | |
CWE Content Team | MITRE | updated Mapping_Notes |