OpenVPN Access Server是美国OpenVPN公司的一款全功能的SSL VPN软件解决方案。 OpenVPN Access Server 2.1.4版本中的Web界面存在CRLF注入漏洞。远程攻击者可通过向 __session_start__/发送PATH_INFO中的‘%0A’字符利用该漏洞注入任意的HTTP包头,实施会话固定攻击和HTTP响应拆分攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation attacks and possibly HTTP response splitting attacks via "%0A" characters in the PATH_INFO to __session_start__/. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-5868.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2016-6256 | SAP Business One for Android 安全漏洞 | |
| CVE-2017-7236 | NetApp OnCommand Unified Manager Core Package SQL注入漏洞 | |
| CVE-2017-7439 | NetApp OnCommand Unified Manager Core Package 安全漏洞 | |
| CVE-2017-9032 | Trend Micro ServerProtect for Linux 跨站脚本漏洞 | |
| CVE-2017-9033 | Trend Micro ServerProtect for Linux 跨站请求伪造漏洞 | |
| CVE-2017-9034 | Trend Micro ServerProtect for Linux 输入验证错误漏洞 | |
| CVE-2017-9035 | Trend Micro ServerProtect for Linux 安全漏洞 | |
| CVE-2017-9036 | Trend Micro ServerProtect for Linux 安全漏洞 | |
| CVE-2017-9037 | Trend Micro ServerProtect for Linux 跨站脚本漏洞 | |
| CVE-2015-5211 | Pivotal Spring Framework 安全漏洞 |
No comments yet