7.5
CVSSv2

CVE-2006-6697

Published: 22/12/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and previous versions, including 9.0.2, allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle application server portal 10g

oracle application server portal 9.0.2

Exploits

source: wwwsecurityfocuscom/bid/21686/info Oracle Portal is prone to multiple HTTP response-splitting vulnerabilities because the application fails to properly sanitize user-supplied input A remote attacker may exploit these vulnerabilities to influence or misrepresent how web content is served, cached, or interpreted This could aid i ...