CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response. <a href"http://cwe.mitre.org/data/definitions/93.html" target"_blank">CWE-93: CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')</a>
Publication date: Fri, 20 Feb 2015 17:59:00 +0000