PoC Index

CVE-2006-6697

HIGH 7.5EPSS 10.6%

CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
10.64% chance of exploitation in the next 30 days, 95th percentile
Published
2006-12-22
Updated
2024-08-07

ExploitDB entries (1)

References

Related