← Back

CVE-2010-4410

nvd nist
Published: Dec 6, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

Affected (174)

2 products
Cgi.pm
Cgi Simple
Configuration A
174 vulnerable
Vulnerable SoftwareAffected Versions
Andy Armstrong
Up to 3.49
Version 1.42
Version 1.43
Version 1.44
Version 1.45
Version 1.4
Version 1.50
Version 1.51
Version 1.52
Version 1.53
Version 1.54
Version 1.55
Version 1.56
Version 1.57
Version 2.01
Version 2.0
Version 2.13
Version 2.14
Version 2.15
Version 2.16
Version 2.17
Version 2.18
Version 2.19
Version 2.20
Version 2.21
Version 2.22
Version 2.23
Version 2.24
Version 2.25
Version 2.26
Version 2.27
Version 2.28
Version 2.29
Version 2.30
Version 2.31
Version 2.32
Version 2.33
Version 2.34
Version 2.35
Version 2.36
Version 2.37
Version 2.38
Version 2.39
Version 2.40
Version 2.41
Version 2.42
Version 2.43
Version 2.44
Version 2.45
Version 2.46
Version 2.47
Version 2.48
Version 2.49
Version 2.50
Version 2.51
Version 2.52
Version 2.53
Version 2.54
Version 2.55
Version 2.56
Version 2.57
Version 2.58
Version 2.59
Version 2.60
Version 2.61
Version 2.62
Version 2.63
Version 2.64
Version 2.65
Version 2.66
Version 2.67
Version 2.68
Version 2.69
Version 2.70
Version 2.71
Version 2.72
Version 2.73
Version 2.74
Version 2.751
Version 2.752
Version 2.75
Version 2.76
Version 2.77
Version 2.78
Version 2.79
Version 2.80
Version 2.81
Version 2.82
Version 2.83
Version 2.84
Version 2.85
Version 2.86
Version 2.87
Version 2.88
Version 2.89
Version 2.90
Version 2.91
Version 2.92
Version 2.93
Version 2.94
Version 2.95
Version 2.96
Version 2.97
Version 2.98
Version 2.99
Version 3.00
Version 3.01
Version 3.02
Version 3.03
Version 3.04
Version 3.05
Version 3.06
Version 3.07
Version 3.08
Version 3.09
Version 3.10
Version 3.11
Version 3.12
Version 3.13
Version 3.14
Version 3.15
Version 3.16
Version 3.17
Version 3.18
Version 3.19
Version 3.20
Version 3.21
Version 3.22
Version 3.23
Version 3.24
Version 3.25
Version 3.26
Version 3.27
Version 3.28
Version 3.29
Version 3.30
Version 3.31
Version 3.32
Version 3.33
Version 3.34
Version 3.35
Version 3.36
Version 3.37
Version 3.38
Version 3.39
Version 3.40
Version 3.41
Version 3.42
Version 3.43
Version 3.44
Version 3.45
Version 3.46
Version 3.47
Version 3.48
Andy Armstrong
Up to 1.112
Version 0.078
Version 0.079
Version 0.080
Version 0.081
Version 0.082
Version 0.83
Version 1.0
Version 1.1.1
Version 1.1.2
Version 1.103
Version 1.104
Version 1.105
Version 1.106
Version 1.107
Version 1.108
Version 1.109
Version 1.110
Version 1.111
Version 1.1

References (48)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.