Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-6697

CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.34
EPSS Ranking 96.7%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2006-6697


Contact Us

Shodan ® - All rights reserved