cbcvebase.
CVE-2005-3751
published 2005-11-22

CVE-2005-3751: HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and…

PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.47%
70.4th percentile
HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers.

Affected

11 ranges
VendorProductVersion rangeFixed in
apsispound<= 1.9.3
apsispound<= 2.7
apsispound>= 0 < 1.9.4-11.9.4-1
apsispound>= 0 < 2.8-22.8-2
apsispound>= 0 < 1.9.4-11.9.4-1
apsispound>= 0 < 2.8-22.8-2
apsispound>= 0 < 1.9.4-11.9.4-1
apsispound>= 0 < 2.8-22.8-2
debiandebian_linux
debianpound< pound 2.8-2 (bullseye)pound 2.8-2 (bullseye)
debianpound< pound 1.9.4-1 (bullseye)pound 1.9.4-1 (bullseye)

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.