CVE-2011-1895 Information

Description

CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold Update 1 Update 2 and SP1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks via unspecified vectors aka \ExcelTable Response Splitting XSS Vulnerability.\

Reference

http://osvdb.org/76235 http://www.securityfocus.com/bid/49979 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-079 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A13064

Share on: