CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
References
Configurations
Information
Published : 2007-12-05 03:46
Updated : 2009-06-09 22:09
NVD link : CVE-2007-5615
Mitre link : CVE-2007-5615
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
mortbay_jetty
- jetty