5

CVE-2012-5572

CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different vulnerability than CVE-2012-5526.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DancerDancer Version <= 1.3113
DancerDancer Version1.150
DancerDancer Version1.3060
DancerDancer Version1.3071
DancerDancer Version1.3079_3
DancerDancer Version1.3079_5
DancerDancer Version1.3110
DancerDancer Version1.3111
DancerDancer Version1.3111_01
DancerDancer Version1.3112
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.639
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.