Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2015-5739

The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as demonstrated by "Content Length" instead of "Content-Length."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.109
EPSS Ranking 93.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
References
Products affected by CVE-2015-5739


Contact Us

Shodan ® - All rights reserved