CVE-2022-40870 Information
Nov 25, 2022
cve
Description
The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a crafted payload injected into the Host header.
Reference
https://github.com/IthacaLabs/Parallels/tree/main/ParallelsRemoteApplicationServer https://github.com/IthacaLabs/Parallels/blob/main/ParallelsRemoteApplicationServer/HHI_CVE-2022-40870.txt
Share on: