CVE-2015-5204

4 documents4 sources
Severity
4.3MEDIUM
EPSS
1.0%
top 22.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 17
Latest updateMay 17

Description

CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android before 1.3.0 allows remote attackers to inject arbitrary headers via CRLF sequences in the filename of an uploaded file.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-5cr8-pc55-3vrc: CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android before 12022-05-17
CVEList
CVE-2015-5204: CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android before 12015-12-17

💥Exploits & PoCs

1
Exploit-DB
AVG Internet Security 2015.0.5315 - Arbitrary Write Privilege Escalation2015-02-04
CVE-2015-5204 (MEDIUM CVSS 4.3) | CRLF injection vulnerability in the | cvebase.io