← Back

CVE-2010-2761

nvd nist
Published: Dec 6, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

Affected (174)

2 products
Cgi.pm
Cgi Simple
Configuration A
174 vulnerable
Vulnerable SoftwareAffected Versions
Andy Armstrong
Up to 3.49
Version 1.42
Version 1.43
Version 1.44
Version 1.45
Version 1.4
Version 1.50
Version 1.51
Version 1.52
Version 1.53
Version 1.54
Version 1.55
Version 1.56
Version 1.57
Version 2.01
Version 2.0
Version 2.13
Version 2.14
Version 2.15
Version 2.16
Version 2.17
Version 2.18
Version 2.19
Version 2.20
Version 2.21
Version 2.22
Version 2.23
Version 2.24
Version 2.25
Version 2.26
Version 2.27
Version 2.28
Version 2.29
Version 2.30
Version 2.31
Version 2.32
Version 2.33
Version 2.34
Version 2.35
Version 2.36
Version 2.37
Version 2.38
Version 2.39
Version 2.40
Version 2.41
Version 2.42
Version 2.43
Version 2.44
Version 2.45
Version 2.46
Version 2.47
Version 2.48
Version 2.49
Version 2.50
Version 2.51
Version 2.52
Version 2.53
Version 2.54
Version 2.55
Version 2.56
Version 2.57
Version 2.58
Version 2.59
Version 2.60
Version 2.61
Version 2.62
Version 2.63
Version 2.64
Version 2.65
Version 2.66
Version 2.67
Version 2.68
Version 2.69
Version 2.70
Version 2.71
Version 2.72
Version 2.73
Version 2.74
Version 2.751
Version 2.752
Version 2.75
Version 2.76
Version 2.77
Version 2.78
Version 2.79
Version 2.80
Version 2.81
Version 2.82
Version 2.83
Version 2.84
Version 2.85
Version 2.86
Version 2.87
Version 2.88
Version 2.89
Version 2.90
Version 2.91
Version 2.92
Version 2.93
Version 2.94
Version 2.95
Version 2.96
Version 2.97
Version 2.98
Version 2.99
Version 3.00
Version 3.01
Version 3.02
Version 3.03
Version 3.04
Version 3.05
Version 3.06
Version 3.07
Version 3.08
Version 3.09
Version 3.10
Version 3.11
Version 3.12
Version 3.13
Version 3.14
Version 3.15
Version 3.16
Version 3.17
Version 3.18
Version 3.19
Version 3.20
Version 3.21
Version 3.22
Version 3.23
Version 3.24
Version 3.25
Version 3.26
Version 3.27
Version 3.28
Version 3.29
Version 3.30
Version 3.31
Version 3.32
Version 3.33
Version 3.34
Version 3.35
Version 3.36
Version 3.37
Version 3.38
Version 3.39
Version 3.40
Version 3.41
Version 3.42
Version 3.43
Version 3.44
Version 3.45
Version 3.46
Version 3.47
Version 3.48
Andy Armstrong
Up to 1.112
Version 0.078
Version 0.079
Version 0.080
Version 0.081
Version 0.082
Version 0.83
Version 1.0
Version 1.1.1
Version 1.1.2
Version 1.103
Version 1.104
Version 1.105
Version 1.106
Version 1.107
Version 1.108
Version 1.109
Version 1.110
Version 1.111
Version 1.1

References (70)

Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.