CVE-2016-5699
PoC —CVSS 3.0
6.1 medium
EPSS
10%p95
Published
()
Modified
Description
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.
- Vendors
- python
- Products
- python
- Weakness
- CWE-113
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.