3.5
CVSSv2

CVE-2010-0155

Published: 14/09/2010 Updated: 10/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware prior to 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm proventia_network_mail_security_system_virtual_appliance

ibm proventia_network_mail_security_system_virtual_appliance_firmware 1.6

Exploits

Web-based Local Management Interface (LMI) of IBM Proventia Network Mail Security System appliance (firmware 16) is vulnerable to a CRLF Injection vulnerability When exploited by an authenticated attacker, such vulnerability could lead to compromising the security of the appliance, allowing injection of custom HTTP cookies, forcing external redir ...