|
|
| |
|
| |
rubygem-actionpack: HTTP response splitting
| Package(s): | rubygem-actionpack |
CVE #(s): | CVE-2008-5189
|
| Created: | March 2, 2009 |
Updated: | December 10, 2009 |
| Description: |
From the Red Hat bugzilla entry:
CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows
remote attackers to inject arbitrary HTTP headers and conduct HTTP
response splitting attacks via a crafted URL to the redirect_to
function.
|
| Alerts: |
|
( Log in to post comments)
|
|
|