Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fg5q-r2q5-qmh3

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Drupal CRLF injection vulnerability in the drupal_set_header function

CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module that allows user-submitted data to appear in HTTP headers.

Пакеты

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 6.0, < 6.38

6.38

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 6.0, < 6.38

6.38

EPSS

Процентиль: 65%
0.00497
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-113

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 9 лет назад

CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module that allows user-submitted data to appear in HTTP headers.

CVSS3: 5.9
nvd
около 9 лет назад

CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module that allows user-submitted data to appear in HTTP headers.

CVSS3: 5.9
debian
около 9 лет назад

CRLF injection vulnerability in the drupal_set_header function in Drup ...

EPSS

Процентиль: 65%
0.00497
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-113