{"api_version":"1","generated_at":"2026-07-23T09:58:34+00:00","cve":"CVE-2005-3751","urls":{"html":"https://cve.report/CVE-2005-3751","api":"https://cve.report/api/cve/CVE-2005-3751.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3751","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3751"},"summary":{"title":"CVE-2005-3751","description":"HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-11-22 20:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/20510","name":"http://secunia.com/advisories/20510","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Gentoo update for pound - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2005/dsa-934","name":"http://www.debian.org/security/2005/dsa-934","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Page not found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.apsis.ch/pound/pound_list/archive/2005/2005-10/1129827166000/index_html?fullMode=1#1129827166000","name":"http://www.apsis.ch/pound/pound_list/archive/2005/2005-10/1129827166000/index_html?fullMode=1#1129827166000","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ANNOUNCE: Pound - reverse proxy and load balancer - v1.9.4 / Robert Segall","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/18381","name":"http://secunia.com/advisories/18381","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Debian update for pound","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200606-05.xml","name":"http://www.gentoo.org/security/en/glsa/glsa-200606-05.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux Documentation\n--\n  Pound: HTTP request smuggling","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2006_05_19.html","name":"http://www.novell.com/linux/security/advisories/2006_05_19.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/20215","name":"http://secunia.com/advisories/20215","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SUSE Updates for Multiple Packages - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18367","name":"http://secunia.com/advisories/18367","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Pound HTTP Request Smuggling Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3751","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3751","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3751","vulnerable":"1","versionEndIncluding":"1.9.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apsis","cpe5":"pound","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:24:36.215Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"DSA-934","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2005/dsa-934"},{"name":"18367","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18367"},{"name":"SUSE-SR:2006:011","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2006_05_19.html"},{"name":"[pound-list] 20051020 ANNOUNCE: Pound - reverse proxy and load balancer - v1.9.4","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.apsis.ch/pound/pound_list/archive/2005/2005-10/1129827166000/index_html?fullMode=1#1129827166000"},{"name":"GLSA-200606-05","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200606-05.xml"},{"name":"20215","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/20215"},{"name":"18381","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18381"},{"name":"20510","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/20510"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-10-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2006-01-12T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"DSA-934","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2005/dsa-934"},{"name":"18367","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18367"},{"name":"SUSE-SR:2006:011","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2006_05_19.html"},{"name":"[pound-list] 20051020 ANNOUNCE: Pound - reverse proxy and load balancer - v1.9.4","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.apsis.ch/pound/pound_list/archive/2005/2005-10/1129827166000/index_html?fullMode=1#1129827166000"},{"name":"GLSA-200606-05","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200606-05.xml"},{"name":"20215","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/20215"},{"name":"18381","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18381"},{"name":"20510","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/20510"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3751","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"DSA-934","refsource":"DEBIAN","url":"http://www.debian.org/security/2005/dsa-934"},{"name":"18367","refsource":"SECUNIA","url":"http://secunia.com/advisories/18367"},{"name":"SUSE-SR:2006:011","refsource":"SUSE","url":"http://www.novell.com/linux/security/advisories/2006_05_19.html"},{"name":"[pound-list] 20051020 ANNOUNCE: Pound - reverse proxy and load balancer - v1.9.4","refsource":"MLIST","url":"http://www.apsis.ch/pound/pound_list/archive/2005/2005-10/1129827166000/index_html?fullMode=1#1129827166000"},{"name":"GLSA-200606-05","refsource":"GENTOO","url":"http://www.gentoo.org/security/en/glsa/glsa-200606-05.xml"},{"name":"20215","refsource":"SECUNIA","url":"http://secunia.com/advisories/20215"},{"name":"18381","refsource":"SECUNIA","url":"http://secunia.com/advisories/18381"},{"name":"20510","refsource":"SECUNIA","url":"http://secunia.com/advisories/20510"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3751","datePublished":"2005-11-22T20:00:00.000Z","dateReserved":"2005-11-22T00:00:00.000Z","dateUpdated":"2024-08-07T23:24:36.215Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-11-22 20:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apsis:pound:*:*:*:*:*:*:*:*","versionEndIncluding":"1.9.3","matchCriteriaId":"74C9DD01-8352-4591-8C78-040A48834545"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3751","Ordinal":"1","Title":"CVE-2005-3751","CVE":"CVE-2005-3751","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3751","Ordinal":"1","NoteData":"HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers.","Type":"Description","Title":"CVE-2005-3751"},{"CveYear":"2005","CveId":"3751","Ordinal":"2","NoteData":"2005-11-22","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3751","Ordinal":"3","NoteData":"2006-01-12","Type":"Other","Title":"Modified"}]}}}