Arnold Grossmann

1 exploit Active since Mar 2006
CVE-2006-1039 EXPLOITDB text WORKING POC
SAP Web Application Server - HTTP Response Injection via Encoded Headers
SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers.