漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
N/A
漏洞信息
A vulnerability in the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a HTTP response splitting attack. The vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by injecting malicious HTTP headers, controlling the response body, or splitting the response into multiple responses. An exploit could allow the attacker to perform cross-site scripting attacks, cross-user defacement, web cache poisoning, and similar exploits. Cisco Bug IDs: CSCvf16705.
漏洞信息
N/A
漏洞
HTTP头部中CRLF序列转义处理不恰当(HTTP响应分割)
漏洞
Cisco Email Security Appliance 安全漏洞
漏洞信息
Cisco Email Security Appliance(ESA)是美国思科(Cisco)公司的一套电子邮件安全设备。该设备提供垃圾邮件保护、邮件加密、数据丢失防护等功能。 Cisco ESA中存在HTTP响应拆分漏洞,该漏洞应用程序或环境没有正确的过滤输入值。远程攻击者可通过注入恶意的HTTP包头,控制响应主体或将相应拆分成多个响应利用该漏洞实施跨站脚本攻击,跨用户污损攻击或Web缓存中毒攻击。
漏洞信息
N/A
漏洞
N/A