CVE-2016-6484: CRLF Injection
Published Jan 23, 2017
·Updated
CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the contentType parameter in a login action to config/userAdmin/login.tdf.
Affected Software
1 affected component
Infoblox NETMRI<=7.0.1
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6484?
CVE-2016-6484 has a medium severity rating, indicating a moderate risk of exploitation.
2
How do I fix CVE-2016-6484?
To fix CVE-2016-6484, upgrade Infoblox NetMRI to version 7.1.1 or later.
3
What types of attacks can be executed through CVE-2016-6484?
CVE-2016-6484 allows attackers to conduct HTTP response splitting attacks by injecting arbitrary HTTP headers.
4
Which versions of Infoblox NetMRI are affected by CVE-2016-6484?
CVE-2016-6484 affects Infoblox NetMRI versions up to and including 7.0.1.
5
What parameter is exploited in CVE-2016-6484?
The contentType parameter in the login action to config/userAdmin/login.tdf is exploited in CVE-2016-6484.