CVE-2016-6816
HIGHApache Tomcat 6.0.0-6.0.47, 7.0.0-7.0.72, 8.0.0.RC1-8.0.38, 8.5.0-8.5.6, 9.0.0.M1-9.0.0.M11 - HTTP Response Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-6816. PoCs published by justpentest.
AI-analyzed exploit summary This exploit demonstrates a security bypass vulnerability in Apache Tomcat by injecting invalid characters into HTTP requests, potentially leading to cache poisoning, XSS, or information disclosure. The PoC provides specific HTTP GET requests that manipulate the response.
Description
The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.
Exploits (1)
This exploit demonstrates a security bypass vulnerability in Apache Tomcat by injecting invalid characters into HTTP requests, potentially leading to cache poisoning, XSS, or information disclosure. The PoC provides specific HTTP GET requests that manipulate the response.
References (36)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L