CVE-2010-4410
published 2010-12-06CVE-2010-4410: CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.04%
79.2th percentile
CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.
Affected
183 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| andy_armstrong | cgi-simple | <= 1.112 | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi-simple | — | — |
| andy_armstrong | cgi.pm | <= 3.49 | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
| andy_armstrong | cgi.pm | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-40927: CGI::Simple versions before 1
osv·2025-08-29·CVSS 4.3
CVE-2025-40927 [MEDIUM] CVE-2025-40927: CGI::Simple versions before 1
CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows HTTP response header injection, which can be used for reflected XSS or open redirect under certain conditions. Although some validation exists, it can be bypassed using URL-encoded values, allowing an attacker to inject untrusted content into the response via query parameters. As a result, an attacker can inject a line break (e.g. %0A) into the parameter value, causing the server to split the HTTP response and inject arbitrary headers or even an HTML/JavaScript body, leading to reflected cross-site scripting (XSS), open redirect or other attacks. The issue documented in CVE-2010-4410 https://www.cve.org/CVERecord?id=CVE-2010
GHSA
GHSA-wh29-fq99-4ww5: CGI::Simple versions before 1
ghsa_unreviewed·2025-08-29·CVSS 4.3
CVE-2025-40927 [MEDIUM] CWE-113 GHSA-wh29-fq99-4ww5: CGI::Simple versions before 1
CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw
This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows HTTP response header injection, which can be used for reflected XSS or open redirect under certain conditions.
Although some validation exists, it can be bypassed using URL-encoded values, allowing an attacker to inject untrusted content into the response via query parameters.
As a result, an attacker can inject a line break (e.g. %0A) into the parameter value, causing the server to split the HTTP response and inject arbitrary headers or even an HTML/JavaScript body, leading to reflected cross-site scripting (XSS), open redirect or other attacks.
The issue documented in CVE-2010-4410 https://www.cve.org/CVERecord?id=CVE-
GHSA
GHSA-63qf-cwcv-ff3r: CRLF injection vulnerability in the header function in (1) CGI
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2010-4410 [MEDIUM] CWE-94 GHSA-63qf-cwcv-ff3r: CRLF injection vulnerability in the header function in (1) CGI
CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.
OSV
CVE-2010-4410: CRLF injection vulnerability in the header function in (1) CGI
osv·2010-12-06·CVSS 4.3
CVE-2010-4410 [MEDIUM] CVE-2010-4410: CRLF injection vulnerability in the header function in (1) CGI
CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.
Debian
CVE-2025-40927: libcgi-simple-perl - CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw Th...
vendor_debian·2025·CVSS 4.3
CVE-2025-40927 [MEDIUM] CVE-2025-40927: libcgi-simple-perl - CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw Th...
CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows HTTP response header injection, which can be used for reflected XSS or open redirect under certain conditions. Although some validation exists, it can be bypassed using URL-encoded values, allowing an attacker to inject untrusted content into the response via query parameters. As a result, an attacker can inject a line break (e.g. %0A) into the parameter value, causing the server to split the HTTP response and inject arbitrary headers or even an HTML/JavaScript body, leading to reflected cross-site scripting (XSS), open redirect or other attacks. The issue documented in CVE-2010-4410 https://www.cve.org/CVERecord?id=CVE-2010
Ubuntu
Perl vulnerabilities
vendor_ubuntu·2011-05-03·CVSS 7.5
CVE-2010-2761 [HIGH] Perl vulnerabilities
Title: Perl vulnerabilities
Summary: An attacker could send crafted input to Perl and bypass intended
restrictions.
It was discovered that the Safe.pm Perl module incorrectly handled
Safe::reval and Safe::rdo access restrictions. An attacker could use this
flaw to bypass intended restrictions and possibly execute arbitrary code.
(CVE-2010-1168, CVE-2010-1447)
It was discovered that the CGI.pm Perl module incorrectly handled certain
MIME boundary strings. An attacker could use this flaw to inject arbitrary
HTTP headers and perform HTTP response splitting and cross-site scripting
attacks. This issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 10.04 LTS and
10.10. (CVE-2010-2761, CVE-2010-4411)
It was discovered that the CGI.pm Perl module incorrectly handled newline
characters. An attacker
Red Hat
perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
vendor_redhat·2010-11-10·CVSS 4.3
CVE-2010-4410 [MEDIUM] perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.
Red Hat
perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
vendor_redhat·2010-11-10·CVSS 4.3
CVE-2010-2761 [MEDIUM] perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
perl-CGI-Simple: - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.
Debian
CVE-2010-4410: libcgi-pm-perl - CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 an...
vendor_debian·2010·CVSS 4.3
CVE-2010-4410 [MEDIUM] CVE-2010-4410: libcgi-pm-perl - CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 an...
CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.
Scope: local
bookworm: resolved (fixed in 3.50-1)
bullseye: resolved (fixed in 3.50-1)
forky: resolved (fixed in 3.50-1)
sid: resolved (fixed in 3.50-1)
trixie: resolved (fixed in 3.50-1)
No detection rules found.
No public exploits indexed.
Bugzilla
perl-CGI, perl-CGI-Simple: CVE-2010-2761 - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting [fedora-all]
bugzilla·2011-10-05·CVSS 4.3
CVE-2010-2761 [MEDIUM] perl-CGI, perl-CGI-Simple: CVE-2010-2761 - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting [fedora-all]
perl-CGI, perl-CGI-Simple: CVE-2010-2761 - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.f
Bugzilla
perl-CGI-Simple: CRLF injection vulnerability via a crafted URL
bugzilla·2010-12-01·CVSS 2.6
[LOW] perl-CGI-Simple: CRLF injection vulnerability via a crafted URL
perl-CGI-Simple: CRLF injection vulnerability via a crafted URL
Masahiro Yamada reported a CRLF injection vulnerability in perl-CGI-Simple
module, allowing remote attackers to inject arbitrary HTTP headers and
content, and conduct HTTP response splitting attacks, via a crafted URL.
References:
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=600464
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=600464#c13
[3] https://bugzilla.mozilla.org/show_bug.cgi?id=600464#c31
[4] https://github.com/digg/stream/issues#issue/1
[5] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3172
Upstream changeset:
[6] https://github.com/AndyA/CGI--Simple/commit/e4942b871a26c1317a175a91ebb7262eea59b380
Note: New CVE identifier (against [5]) has been requested for the occurrence
of this issue in perl-CGI-S
Bugzilla
perl-CGI, perl-CGI-Simple: CVE-2010-2761 - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
bugzilla·2010-12-01·CVSS 4.3
CVE-2010-2761 [MEDIUM] perl-CGI, perl-CGI-Simple: CVE-2010-2761 - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
perl-CGI, perl-CGI-Simple: CVE-2010-2761 - hardcoded MIME boundary value for multipart content, CVE-2010-4410 - CRLF injection allowing HTTP response splitting
1, perl-CGI package issues description:
Masahiro Yamada reported a CRLF injection vulnerability in perl-CGI
module, allowing remote attackers to inject arbitrary HTTP headers and
content, and conduct HTTP response splitting attacks, via a crafted URL.
References:
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=600464
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=600464#c29
[3] https://github.com/digg/stream/issues#issue/1
[4] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3172
Upstream changeset:
[5] http://www2.rbfh.de/cgi/cgit.cgi/perl5.git/commit/?id=84601d63a7e34958da47dad1e61e27cb3bd467d1
Note: New CVE identifier
Bugzilla
perl-CGI-Simple: CVE-2010-2761 -- hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, CVE-2010-4410 -- CRLF injection vulnerability in the header function flaws [fedora-a
bugzilla·2010-12-01·CVSS 4.3
CVE-2010-2761 [MEDIUM] perl-CGI-Simple: CVE-2010-2761 -- hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, CVE-2010-4410 -- CRLF injection vulnerability in the header function flaws [fedora-a
perl-CGI-Simple: CVE-2010-2761 -- hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, CVE-2010-4410 -- CRLF injection vulnerability in the header function flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update s
http://cpansearch.perl.org/src/LDS/CGI.pm-3.50/Changeshttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053576.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/053591.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://openwall.com/lists/oss-security/2010/12/01/1http://openwall.com/lists/oss-security/2010/12/01/2http://openwall.com/lists/oss-security/2010/12/01/3http://perl5.git.perl.org/perl.git/blobdiff/a0b94c2432b1d8c20653453a0f6970cb10f59aec..84601d63a7e34958da47dad1e61e27cb3bd467d1:/cpan/CGI/lib/CGI.pmhttp://perl5.git.perl.org/perl.git/commit/84601d63a7e34958da47dad1e61e27cb3bd467d1http://secunia.com/advisories/43068http://secunia.com/advisories/43147http://www.mandriva.com/security/advisories?name=MDVSA-2010:237http://www.mandriva.com/security/advisories?name=MDVSA-2010:252http://www.nntp.perl.org/group/perl.perl5.changes/2010/11/msg28043.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1797.htmlhttp://www.securityfocus.com/bid/44199http://www.securityfocus.com/bid/45145http://www.vupen.com/english/advisories/2010/3230http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0249https://bugzilla.redhat.com/show_bug.cgi?id=658970http://cpansearch.perl.org/src/LDS/CGI.pm-3.50/Changeshttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053576.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/053591.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://openwall.com/lists/oss-security/2010/12/01/1http://openwall.com/lists/oss-security/2010/12/01/2http://openwall.com/lists/oss-security/2010/12/01/3http://perl5.git.perl.org/perl.git/blobdiff/a0b94c2432b1d8c20653453a0f6970cb10f59aec..84601d63a7e34958da47dad1e61e27cb3bd467d1:/cpan/CGI/lib/CGI.pmhttp://perl5.git.perl.org/perl.git/commit/84601d63a7e34958da47dad1e61e27cb3bd467d1http://secunia.com/advisories/43068http://secunia.com/advisories/43147http://www.mandriva.com/security/advisories?name=MDVSA-2010:237http://www.mandriva.com/security/advisories?name=MDVSA-2010:252http://www.nntp.perl.org/group/perl.perl5.changes/2010/11/msg28043.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1797.htmlhttp://www.securityfocus.com/bid/44199http://www.securityfocus.com/bid/45145http://www.vupen.com/english/advisories/2010/3230http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0249https://bugzilla.redhat.com/show_bug.cgi?id=658970
2010-12-06
Published