Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9964

Опубликовано: 16 дек. 2016
Источник: nvd
CVSS3: 6.5
CVSS2: 4.3
EPSS Низкий

Описание

redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bottlepy:bottle:0.12.10:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.01087
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 9 лет назад

redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.

CVSS3: 6.5
debian
около 9 лет назад

redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequ ...

CVSS3: 6.5
github
больше 3 лет назад

bottle.py vulnerable to CRLF Injection

EPSS

Процентиль: 77%
0.01087
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-93