CWE-113

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

Parent: CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')

The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.

97 vulnerabilities with CWE-113
CVE-2018-16181 MEDIUM
i-FILTER <9.50R05 - HTTP Header Injection
CVSS 6.1
CVE-2018-0689 HIGH
SEIKO EPSON - HTTP Header Injection
CVSS 8.8
CVE-2018-13814 HIGH
SIMATIC HMI and WinCC < V14 - HTTP Header Injection via Integrated Web Server
CVSS 8.8
CVE-2018-11347 HIGH
YunoHost 2.7.2-2.7.14 - HTTP Response Header Injection
CVSS 8.8
CVE-2018-7830 HIGH
Modicon M340, Premium, Quantum, and BMXNOR0200 Firmware - Denial of Service via HTTP Response Splitting
CVSS 7.5
CVE-2018-16979 MEDIUM
Monstra CMS V3.0.4 - HTTP Header Injection
CVSS 6.1
CVE-2018-3911 HIGH
Samsung SmartThings Hub STH-ETH-250 - Firmware 0.20.17 - HTTP Heade...
CVSS 8.6
CVE-2018-1067 MEDIUM
Undertow <7.1.2.CR1-7.1.2.GA - Command Injection
CVSS 6.1
CVE-2017-7528 MEDIUM
Ansible Tower - CRLF Injection via X-Forwarded-For Header
CVSS 5.2
CVE-2017-17742 MEDIUM
Ruby <2.2.10-2.6.0 - Info Disclosure
CVSS 5.3
CVE-2017-12308 MEDIUM
Cisco Small Business Managed Switches - HTTP Response Splitting
CVSS 6.1
CVE-2017-1262 MEDIUM
IBM Security Guardium 10.0 - HTTP Response Splitting via Crafted URL
CVSS 6.1
CVE-2017-12309 MEDIUM
Cisco Email Security Appliance - XSS
CVSS 5.3
CVE-2017-7443 MEDIUM
apt-cacher <1.7.15-apt-cacher-ng <3.4 - XSS
CVSS 6.1
CVE-2016-8024 HIGH
Intel Security VSEL <2.0.3 - Info Disclosure
CVSS 8.1
CVE-2016-5325 MEDIUM
Node.js HTTP Response Splitting via ServerResponse#writeHead
CVSS 6.1
CVE-2016-4993 MEDIUM
Red Hat JBoss Enterprise Application Platform < 7.0.1 - HTTP Response Splitting via Undertow Web Server
CVSS 6.1
CVE-2016-6839 MEDIUM
Huawei FusionAccess <V100R006C00 - CRLF Injection
CVSS 6.1
CVE-2016-5699 MEDIUM
CPython < 2.7.9 - HTTP Header Injection via CRLF Sequences in HTTPConnection.putheader
CVSS 6.1
CVE-2015-1445 HIGH
fli4l < 3.10.1 and 4.0 before 2015-01-30 - HTTP Header Injection
CVSS 7.2
CVE-2015-0733
Cisco Headend Digital Broadband Delivery System - HTTP Response Splitting via CRLF Injection
CVE-2007-5595
Drupal <4.7.8, <5.3 - CRLF Injection
Details
Vulnerabilities 97