CVE Vulnerabilities

CVE-2015-5204

Published: Dec 17, 2015 | Modified: Dec 18, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android before 1.3.0 allows remote attackers to inject arbitrary headers via CRLF sequences in the filename of an uploaded file.

Affected Software

Name Vendor Start Version End Version
Cordova_file_transfer Apache * 1.2.1 (including)

References