PT-2016-5395 · Php+1 · Php+1

Pere Orga

·

Publicado

2016-04-12

·

Atualizado

2022-05-17

·

CVE-2016-3166

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Drupal versions 6.x before 6.38
Description A CRLF injection issue exists in the drupal set header function when used with PHP before 5.1.2, allowing remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module that allows user-submitted data to appear in HTTP headers.
Recommendations For Drupal versions 6.x before 6.38, update to version 6.38 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-3166
GHSA-FG5Q-R2Q5-QMH3

Produtos afetados

Drupal
Php