CRLF Injection Vulnerability in Microsoft Forefront Unified Access Gateway
CVE-2011-1895
Currently unrated
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 12 October 2011
Summary
A CRLF injection vulnerability exists in Microsoft Forefront Unified Access Gateway 2010, allowing remote attackers to manipulate HTTP headers. This could facilitate HTTP response splitting and enable cross-site scripting (XSS) attacks through unspecified vectors, compromising the security of affected applications.
References
EPSS Score
21% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved