Weakness Name | Source | |
---|---|---|
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers. |
Metrics | Score | Severity | CVSS Vector | Source |
---|---|---|---|---|
V2 | 5.1 | AV:N/AC:H/Au:N/C:P/I:P/A:P | [email protected] |
Drupal>>Drupal >> Version From (including) 4.7.0 To (excluding) 4.7.8
Drupal>>Drupal >> Version From (including) 5.0 To (excluding) 5.3