CVE-2019-6802
25.01.2019, 04:29
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.
Vendor | Product | Version |
---|---|---|
python | pypiserver | 𝑥 ≤ 1.2.5 |
𝑥
= Vulnerable software versions