CVE-2012-5572

Published

Severity

CVSS v3:
N/A
CVSS v2:
5 MEDIUM

Description

CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different vulnerability than CVE-2012-5526.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:dancer:dancer:1.150:*:*:*:*:*:*:*n/an/a1.150
cpe:2.3:a:dancer:dancer:1.3079_5:*:*:*:*:*:*:*n/an/a1.3079_5
cpe:2.3:a:dancer:dancer:1.3079_3:*:*:*:*:*:*:*n/an/a1.3079_3
cpe:2.3:a:dancer:dancer:1.3071:*:*:*:*:*:*:*n/an/a1.3071
cpe:2.3:a:dancer:dancer:*:*:*:*:*:*:*:*n/a1.3113 (including)*
cpe:2.3:a:dancer:dancer:1.3111:*:*:*:*:*:*:*n/an/a1.3111
cpe:2.3:a:dancer:dancer:1.3110:*:*:*:*:*:*:*n/an/a1.3110
cpe:2.3:a:dancer:dancer:1.3112:*:*:*:*:*:*:*n/an/a1.3112
cpe:2.3:a:dancer:dancer:1.3060:*:*:*:*:*:*:*n/an/a1.3060
cpe:2.3:a:dancer:dancer:1.3111_01:*:*:*:*:*:*:*n/an/a1.3111_01

External Links