Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2006-6697
CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.34
EPSS Ranking
96.7%
CVSS Severity
CVSS v2 Score
7.5
References
http://marc.info/?l=full-disclosure&m=116664018702238&w=2
http://marc.info/?l=full-disclosure&m=116666155824901&w=2
http://secunia.com/advisories/23461
http://securityreason.com/securityalert/2057
http://www.securityfocus.com/archive/1/454945/100/0/threaded
http://www.securityfocus.com/archive/1/454965/100/0/threaded
http://www.securityfocus.com/archive/1/455106/100/0/threaded
http://www.securityfocus.com/bid/21686
http://www.vupen.com/english/advisories/2006/5124
http://marc.info/?l=full-disclosure&m=116664018702238&w=2
http://marc.info/?l=full-disclosure&m=116666155824901&w=2
http://secunia.com/advisories/23461
http://securityreason.com/securityalert/2057
http://www.securityfocus.com/archive/1/454945/100/0/threaded
http://www.securityfocus.com/archive/1/454965/100/0/threaded
http://www.securityfocus.com/archive/1/455106/100/0/threaded
http://www.securityfocus.com/bid/21686
http://www.vupen.com/english/advisories/2006/5124
Products affected by CVE-2006-6697
Oracle
»
Application Server Portal
»
Version:
10g
cpe:2.3:a:oracle:application_server_portal:10g
Oracle
»
Application Server Portal
»
Version:
9.0.2
cpe:2.3:a:oracle:application_server_portal:9.0.2
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved