Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-5486

Опубликовано: 30 сент. 2014
Источник: debian

Описание

ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zope2.12fixed2.12.26-1package

Примечания

  • https://plone.org/products/plone/security/advisories/20121106/02

Связанные уязвимости

redhat
почти 13 лет назад

ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

nvd
почти 11 лет назад

ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

CVSS3: 7.5
github
около 7 лет назад

HTTP header injection in Plone and Zope2

oracle-oval
почти 11 лет назад

ELSA-2014-1194: conga security and bug fix update (MODERATE)