|
|
| |
|
| |
perl-CGI: header injection
| Package(s): | perl-CGI |
CVE #(s): | CVE-2012-5526
|
| Created: | November 28, 2012 |
Updated: | December 19, 2012 |
| Description: |
From the CVE entry:
CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm. |
| Alerts: |
|
( Log in to post comments)
|
|
|