Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39875
HistoryMar 21, 2023 - 12:27 a.m.

Special Element Injection

2023-03-2100:27:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
special element injection
user input
telnet options
content negotiation
application vulnerability

0.002 Low

EPSS

Percentile

57.8%

curl is vulnerable to Special Element Injection. The library allows users to pass on user name and telnet options to the server without proper input scrubbing, allowing them to pass on content or do option negotiation without the application intending to do so.