Lucene search

K
httpdApache Team FoundationHTTPD:AA860ED739944CC66DCA320985CEC190
HistoryJan 15, 2008 - 12:00 a.m.

Apache Httpd < 2.2.12 : CRLF injection in mod_negotiation when untrusted uploads are supported

2008-01-1500:00:00
Apache Team Foundation
httpd.apache.org
21

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

0.01 Low

EPSS

Percentile

83.4%

Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_negotiation and allow untrusted uploads to locations which have MultiViews enabled.

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

0.01 Low

EPSS

Percentile

83.4%