VDB
CVE-2005-2088
CVE-2005-2088
PUBLISHED
CVSS 4.300000190734863 MEDIUM
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
EPSS 20.46% · 97.4th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
20.46%
97.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| debian | debian_linux | 3.0, 3.1 |
| n/a | n/a | n/a |
| apache | http_server | 2.0.35 |
Timeline
- Jun 30, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Aug 7, 2024 CVE Updated
- Mar 17, 2025 EPSS Score
- Mar 24, 2025 EPSS Score
- Mar 25, 2025 EPSS Score
- Apr 12, 2025 EPSS Score
- Apr 13, 2025 EPSS Score
- May 1, 2025 EPSS Score
- May 4, 2025 EPSS Score
- Jun 6, 2025 EPSS Score
References
- SUSE-SA:2005:046 vendor-advisory
- PK13959 vendor-advisory
- ADV-2006-1018 vdb
- 14530 third-party-advisory
- oval:org.mitre.oval:def:1237 vdb
- 14106 vdb
- 102197 vendor-advisory
- [httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html mailing-list
- [httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/ mailing-list
- [httpd-cvs] 20210330 svn commit: r1888194 [3/13] - /httpd/site/trunk/content/security/json/ mailing-list
- SUSE-SR:2005:018 vendor-advisory
- USN-160-2 vendor-advisory
- ADV-2005-2140 vdb
- ADV-2005-2659 vdb
- oval:org.mitre.oval:def:840 vdb
- 19185 third-party-advisory
- http://www.apache.org/dist/httpd/CHANGES_2.0 url
- ADV-2006-4680 vdb
- 604 third-party-advisory
- 17487 third-party-advisory
…and 52 more