Логотип exploitDog
bind:CVE-2015-7519
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-7519

Количество 6

Количество 6

ubuntu логотип

CVE-2015-7519

около 10 лет назад

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2015-7519

около 10 лет назад

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2015-7519

около 10 лет назад

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2015-7519

около 10 лет назад

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0. ...

CVSS3: 3.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:2337-1

около 10 лет назад

Security update for rubygem-passenger

EPSS: Низкий
github логотип

GHSA-fxwv-953p-7qpf

больше 7 лет назад

Phusion Passenger allows remote attackers to spoof headers

CVSS3: 3.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-7519

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

CVSS3: 3.7
0%
Низкий
около 10 лет назад
redhat логотип
CVE-2015-7519

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

CVSS2: 5.8
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-7519

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

CVSS3: 3.7
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-7519

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0. ...

CVSS3: 3.7
0%
Низкий
около 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:2337-1

Security update for rubygem-passenger

0%
Низкий
около 10 лет назад
github логотип
GHSA-fxwv-953p-7qpf

Phusion Passenger allows remote attackers to spoof headers

CVSS3: 3.7
0%
Низкий
больше 7 лет назад

Уязвимостей на страницу