Internet Explorer 7 allows the overwrite of headers such as Content-Length, Host and Referer, exposing the browser to HTTP request splitting attacks.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/64798/MSA02240108.txt
Source: https://packetstormsecurity.com/files/64798/MSA02240108.txt.html

