Description
Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes IIS to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
Remediation
References
Related Vulnerabilities
CakePHP Improper Input Validation Vulnerability (CVE-2016-4793)
WordPress Plugin Contact Form by BestWebSoft Cross-Site Scripting (3.95)
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.15.49)
Grafana Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2024-10452)