Vulnerabilities > CVE-2016-1133 - Unspecified vulnerability in Dena H2O

047910
CVSS 3.7 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
high complexity
dena
nessus

Summary

CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URI.

Nessus

NASL familyFreeBSD Local Security Checks
NASL idFREEBSD_PKG_6C808811BB9A11E5A65C485D605F4717.NASL
descriptionYakuzo OKU reports : When redirect directive is used, this flaw allows a remote attacker to inject response headers into an HTTP redirect response.
last seen2020-06-01
modified2020-06-02
plugin id87960
published2016-01-18
reporterThis script is Copyright (C) 2016-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/87960
titleFreeBSD : h2o -- directory traversal vulnerability (6c808811-bb9a-11e5-a65c-485d605f4717)