Loading HuntDB...

Additional information for CVE-2016-5699

I
Internet Bug Bounty
Submitted None
Reported by ecbftw

Vulnerability Details

Technical details and impact analysis

I was not the first to report this issue, but the fix languished for quite some time, since no one realized quite how bad it was. I wasn't aware of the original bug report and discovered the issue independently. I was the first to report the much more serious consequences of it. The vulnerability itself was technically public and fixed, and I waited 6 months to publish the more serious attack scenarios (when a CVE was finally publicly requested). My full description is here: http://blog.blindspotsecurity.com/2016/06/advisory-http-header-injection-in.html

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted