First published: Mon Jan 23 2017(Updated: )
CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the contentType parameter in a login action to config/userAdmin/login.tdf.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
mri | <=7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6484 has a medium severity rating, indicating a moderate risk of exploitation.
To fix CVE-2016-6484, upgrade Infoblox NetMRI to version 7.1.1 or later.
CVE-2016-6484 allows attackers to conduct HTTP response splitting attacks by injecting arbitrary HTTP headers.
CVE-2016-6484 affects Infoblox NetMRI versions up to and including 7.0.1.
The contentType parameter in the login action to config/userAdmin/login.tdf is exploited in CVE-2016-6484.