Total vulnerabilities in the database
CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.
Software | From | Fixed in |
---|---|---|
andy_armstrong / cgi.pm | - | 3.62.x |