Adobe ColdFusion Component Browser CVE-2012-2041 HTTP Response Splitting Vulnerability
BID:53941
Info
Adobe ColdFusion Component Browser CVE-2012-2041 HTTP Response Splitting Vulnerability
| Bugtraq ID: | 53941 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2041 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2012 12:00AM |
| Updated: | Jun 12 2012 12:00AM |
| Credit: | Michael Dominice, Yoshi Russell and Stephen Duncan |
| Vulnerable: |
Adobe ColdFusion 8.0.1 Adobe ColdFusion 9.0.1 Adobe ColdFusion 9.0 Adobe ColdFusion 8.0 |
| Not Vulnerable: | |
Discussion
Adobe ColdFusion Component Browser CVE-2012-2041 HTTP Response Splitting Vulnerability
Adobe ColdFusion is prone to an HTTP response-splitting vulnerability because it fails to sufficiently sanitize user-supplied data.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
Adobe ColdFusion ColdFusion 9.0.1 and prior versions are affected.
Adobe ColdFusion is prone to an HTTP response-splitting vulnerability because it fails to sufficiently sanitize user-supplied data.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
Adobe ColdFusion ColdFusion 9.0.1 and prior versions are affected.
Exploit / POC
Adobe ColdFusion Component Browser CVE-2012-2041 HTTP Response Splitting Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Adobe ColdFusion Component Browser CVE-2012-2041 HTTP Response Splitting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Adobe ColdFusion Component Browser CVE-2012-2041 HTTP Response Splitting Vulnerability
References:
References: