6.1
CVE-2021-20784
- EPSS 0.45%
- Veröffentlicht 14.07.2021 02:15:07
- Zuletzt bearbeitet 03.12.2024 02:15:16
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote attacker to inject an arbitrary script or alter the website that uses the product.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Voidtools ≫ Everything Version < 1.1
Voidtools ≫ Everything Version >= 1.1 < 1.2
Voidtools ≫ Everything Version >= 1.2 < 1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.45% | 0.629 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
| vultures@jpcert.or.jp | 6.1 | 2.8 | 2.7 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax
The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.