CVE-2012-5572

CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different vulnerability than CVE-2012-5526.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dancer:dancer:*:*:*:*:*:*:*:*
cpe:2.3:a:dancer:dancer:1.150:*:*:*:*:*:*:*
cpe:2.3:a:dancer:dancer:1.3060:*:*:*:*:*:*:*
cpe:2.3:a:dancer:dancer:1.3071:*:*:*:*:*:*:*
cpe:2.3:a:dancer:dancer:1.3079_3:*:*:*:*:*:*:*
cpe:2.3:a:dancer:dancer:1.3079_5:*:*:*:*:*:*:*
cpe:2.3:a:dancer:dancer:1.3110:*:*:*:*:*:*:*
cpe:2.3:a:dancer:dancer:1.3111:*:*:*:*:*:*:*
cpe:2.3:a:dancer:dancer:1.3111_01:*:*:*:*:*:*:*
cpe:2.3:a:dancer:dancer:1.3112:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-05-30 14:55

Updated : 2024-02-28 12:20


NVD link : CVE-2012-5572

Mitre link : CVE-2012-5572

CVE.ORG link : CVE-2012-5572


JSON object : View

Products Affected

dancer

  • dancer
CWE
CWE-20

Improper Input Validation