Skip to content

DMCERTCE/CRLF_Tiny

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 

Repository files navigation

CRLF_Tiny

A CRLF vulnerability (%0D%0A) exists in TinyWeb Server creating a potential risk for redirection, XSS and other cool tricks depending on how the client interprets the HTTP Response. image

This vulnerability also leads to integrity failure, as logfiles can be spoofed:

Example: image

Resulting events in access_log stored in application directory:

image Same most likely evident for agent_ and referer_ logs etc.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published