Perl Dancer.pm CVE-2012-5572 HTTP Header Injection Vulnerability
BID:56711
Info
Perl Dancer.pm CVE-2012-5572 HTTP Header Injection Vulnerability
| Bugtraq ID: | 56711 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5572 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2012 12:00AM |
| Updated: | Apr 13 2015 08:59PM |
| Credit: | vlet |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Perl Dancer.pm CVE-2012-5572 HTTP Header Injection Vulnerability
Perl Dancer.pm is prone to a vulnerability that allows attackers to inject arbitrary HTTP headers because it fails to sufficiently sanitize input.
An attacker may exploit this issue to inject arbitrary HTTP headers into a server response.
By inserting arbitrary headers into an HTTP response, attackers may be able to launch various cross-site request forgery, cross-site scripting, and HTTP-request smuggling attacks.
Perl Dancer.pm is prone to a vulnerability that allows attackers to inject arbitrary HTTP headers because it fails to sufficiently sanitize input.
An attacker may exploit this issue to inject arbitrary HTTP headers into a server response.
By inserting arbitrary headers into an HTTP response, attackers may be able to launch various cross-site request forgery, cross-site scripting, and HTTP-request smuggling attacks.
References
Perl Dancer.pm CVE-2012-5572 HTTP Header Injection Vulnerability
References:
References:
- Cookie name CRLF injection (Dancer.pm)
- Dancer.pm Homepage (Alexis Sukrieh)
- libdancer-perl: CVE-2012-5572: Cookie name CRLF injection (Debian)
- Perl Homepage (Perl.org)