CVE-2011-1895

MEDIUM

Description

CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via unspecified vectors, aka "ExcelTable Response Splitting XSS Vulnerability."

References

http://osvdb.org/76235

http://www.securityfocus.com/bid/49979

https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-079

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13064

Details

Source: MITRE

Published: 2011-10-12

Updated: 2018-10-12

Type: CWE-94

Risk Information

CVSS v2.0

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM