CVE Vulnerabilities

CVE-2006-6697

Published: Dec 22, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter.

Affected Software

NameVendorStart VersionEnd Version
Application_server_portalOracle9.0.2 (including)9.0.2 (including)
Application_server_portalOracle10g (including)10g (including)

References