HTTP header injection vulnerability in i-FILTER Ver.9.50R05 and earlier may allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks that may result in an arbitrary script injection or setting an arbitrary cookie values via unspecified vectors.
The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
Link | Tags |
---|---|
https://jvn.jp/en/jp/JVN32155106/index.html | third party advisory |
https://download.daj.co.jp/user/ifilter/V9/ | permissions required vendor advisory |