Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3154

Опубликовано: 27 янв. 2020
Источник: debian
EPSS Низкий

Описание

CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zendframeworkfixed1.12.12+dfsg-1package
zendframeworkfixed1.12.9+dfsg-2+deb8u1jessiepackage

Примечания

  • http://framework.zend.com/security/advisory/ZF2015-04

EPSS

Процентиль: 50%
0.00274
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.

CVSS3: 6.1
nvd
около 6 лет назад

CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.

CVSS3: 6.1
github
больше 3 лет назад

Zenario CMS vulnerable to CRLF injection

EPSS

Процентиль: 50%
0.00274
Низкий