CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Squid |
Squid-cache |
* |
3.1.0.18 (including) |
References