Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23240
HistoryApr 10, 2020 - 12:20 a.m.

HTTP Request-splitting

2020-04-1000:20:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.089

Percentile

94.6%

SeaMonkey is vulnerable to HTTP request-splitting.A request-splitting flaw was found in the way in which SeaMonkey generates a digest authentication request. If a user opened a specially-crafted URL, it was possible to perform cross-site scripting attacks, web cache poisoning, or other, similar exploits.

References