5
CVSSv2

CVE-2006-5330

Published: 17/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and previous versions for Windows, 7.0.63 and previous versions for Linux, 7.x prior to 7.0 r67 for Solaris, and prior to 9.0.28.0 for Mac OS X, allows remote malicious users to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks via CRLF sequences in arguments to the ActionScript functions (1) XML.addRequestHeader and (2) XML.contentType. NOTE: the flexibility of the attack varies depending on the type of web browser being used.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash player

Vendor Advisories

Debian Bug report logs - #402822 flashplugin-nonfree: HTTP header injection vulnerabilities (CVE-2006-5330) Package: flashplugin-nonfree; Maintainer for flashplugin-nonfree is Bart Martens <bartm@debianorg>; Source for flashplugin-nonfree is src:flashplugin-nonfree (PTS, buildd, popcon) Reported by: Ben Hutchings <ben@de ...