Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the item parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WebCollab ‘item’参数HTTP响应拆分漏洞
Vulnerability Description
WebCollab是一套基于Web的项目管理系统。该系统支持对单个用户设置权限,并可对项目的进展情况用图形突出标记。 WebCollab 3.30及之前的版本中的help/help_language.php脚本中存在CRLF注入漏洞。远程攻击者可借助‘item’参数利用该漏洞插入任意HTTP头,并实施HTTP响应拆分攻击。
CVSS Information
N/A
Vulnerability Type
N/A