CVE-2015-5285
29.10.2015, 20:59
CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the came_from parameter to _admin/login.Enginsight
| Vendor | Product | Version |
|---|---|---|
| kallithea-scm | kallithea | 𝑥 ≤ 0.2 |
𝑥
= Vulnerable software versions
References