4.3
CVSSv2

CVE-2008-3906

Published: 04/09/2008 Updated: 11/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in Sys.Web in Mono 2.0 and previous versions allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.

Vulnerable Product Search on Vulmon Subscribe to Product

mono mono 1.0.5

mono mono 1.1.13

mono mono 1.2.5.1

mono project mono 1.2.1

mono project mono

mono mono 1.1.17.1

mono mono 1.0

mono mono 1.1.4

mono mono 1.1.8.3

mono project mono 1.2.6

mono project mono 1.9

mono mono 1.1.17

mono mono 1.1.18

mono project mono 1.2.4

mono project mono 1.2.5

mono mono 1.1.13.4

mono mono 1.1.13.6

mono mono 1.1.13.7

mono project mono 1.2.2

mono project mono 1.2.3

Vendor Advisories

It was discovered that the XML HMAC signature system did not correctly check certain lengths If an attacker sent a truncated HMAC, it could bypass authentication, leading to potential privilege escalation (CVE-2009-0217) ...
Debian Bug report logs - #494406 CVE-2008-3422: Multiple Cross-site scripting (XSS) vulnerabilities Package: mono; Maintainer for mono is Debian Mono Group <pkg-mono-group@listsaliothdebianorg>; Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Sat, 9 Aug 2008 06:57:01 UTC Severity: important Tags: ...
Debian Bug report logs - #498894 mono: CRLF injection vulnerability Package: mono; Maintainer for mono is Debian Mono Group <pkg-mono-group@listsaliothdebianorg>; Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Sun, 14 Sep 2008 09:46:20 UTC Severity: important Tags: security Fixed in version mono ...

Exploits

source: wwwsecurityfocuscom/bid/30867/info Mono is prone to a vulnerability that allows attackers to inject arbitrary HTTP headers because it fails to sanitize input By inserting arbitrary headers into an HTTP response, attackers may be able to launch cross-site request-forgery, cross-site scripting, HTTP-request-smuggling, and other at ...