cbcvebase.
CVE-2010-3172
published 2010-11-05

CVE-2010-3172: CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web…

low2.6CVSS 3.1
AVNACHAuNCNIPAN
CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HTTP response splitting attacks, via a crafted URL.

Affected

277 ranges· showing 25
VendorProductVersion rangeFixed in
andy_armstrongcgi-simple<= 1.112
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi-simple
andy_armstrongcgi.pm<= 3.49
andy_armstrongcgi.pm
andy_armstrongcgi.pm
andy_armstrongcgi.pm
andy_armstrongcgi.pm

CVSS provenance

nvd4.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM