CWE-113
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
107 vulnerabilities with CWE-113
CVE-2016-5325
MEDIUM
Node.js HTTP Response Splitting via ServerResponse#writeHead
CVSS 6.1
CVE-2016-4993
MEDIUM
Red Hat JBoss Enterprise Application Platform < 7.0.1 - HTTP Response Splitting via Undertow Web Server
CVSS 6.1
CVE-2016-6839
MEDIUM
Huawei FusionAccess <V100R006C00 - CRLF Injection
CVSS 6.1
CVE-2016-5699
MEDIUM
CPython < 2.7.9 - HTTP Header Injection via CRLF Sequences in HTTPConnection.putheader
CVSS 6.1
CVE-2015-1445
HIGH
fli4l < 3.10.1 and 4.0 before 2015-01-30 - HTTP Header Injection
CVSS 7.2
CVE-2015-0733
Cisco Headend Digital Broadband Delivery System - HTTP Response Splitting via CRLF Injection
CVE-2007-5595
Drupal <4.7.8, <5.3 - CRLF Injection
Details
Vulnerabilities
107