Lucene search

K
cvelistMitreCVELIST:CVE-2007-4164
HistoryAug 07, 2007 - 10:00 a.m.

CVE-2007-4164

2007-08-0710:00:00
mitre
www.cve.org
6

AI Score

6.6

Confidence

Low

EPSS

0.037

Percentile

91.9%

CRLF injection vulnerability in the redirect feature in Sun Java System Web Server 6.1 and 7.0 before 20070802, when the redirect Server Application Function (SAF) uses the url-prefix parameter and escape is disabled, or an Error directive uses the url-prefix parameter in obj.conf, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks.

AI Score

6.6

Confidence

Low

EPSS

0.037

Percentile

91.9%

Related for CVELIST:CVE-2007-4164