CVE-2015-5285
29.10.2015, 20:59
CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the came_from parameter to _admin/login.Enginsight
Vendor | Product | Version |
---|---|---|
kallithea-scm | kallithea | 𝑥 ≤ 0.2 |
𝑥
= Vulnerable software versions
References