HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote attacker to inject an arbitrary script or alter the website that uses the product.
The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.
Link | Tags |
---|---|
https://www.voidtools.com/downloads/ | product vendor advisory |
https://www.voidtools.com/ | vendor advisory |
https://jvn.jp/en/jp/JVN68971465/ | |
https://jvn.jp/en/jp/JVN68971465/index.html | third party advisory |