Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX).
Link | Tags |
---|---|
http://www.osvdb.org/18510 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/21553 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2005-07/0434.html | mailing list |