cbcvebase.
CVE-2010-3172
published 2010-11-05

CVE-2010-3172: CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web…

PriorityP413low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
1.79%
76.0th percentile
CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HTTP response splitting attacks, via a crafted URL.

Affected

277 ranges· showing 25
VendorProductVersion rangeFixed in
andy_armstrongcgi-simple<= 1.112
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi.pm<= 3.49
andy_armstrongcgi.pm
andy_armstrongcgi.pm
andy_armstrongcgi.pm
andy_armstrongcgi.pm

CVSS provenance

nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.