5

CVE-2012-5572

CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different vulnerability than CVE-2012-5526.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dancer ≫ Dancer Version <= 1.3113
Dancer ≫ Dancer Version 1.150
Dancer ≫ Dancer Version 1.3060
Dancer ≫ Dancer Version 1.3071
Dancer ≫ Dancer Version 1.3079_3
Dancer ≫ Dancer Version 1.3079_5
Dancer ≫ Dancer Version 1.3110
Dancer ≫ Dancer Version 1.3111
Dancer ≫ Dancer Version 1.3111_01
Dancer ≫ Dancer Version 1.3112
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.5% 0.709
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://advisories.mageia.org/MGASA-2013-0183.html
http://www.mandriva.com/security/advisories?name=MDVSA-2013:184
http://www.openwall.com/lists/oss-security/2012/11/26/10
https://github.com/PerlDancer/Dancer/blob/devel/CHANGES
https://github.com/PerlDancer/Dancer/issues/859
https://lists.fedoraproject.org/pipermail/package-announce/2013-June/108749.html