CVE
- Id
- 96784
- CVE No.
- CVE-2016-9964
- Status
- Candidate
- Description
- redirect() in bottle.py in bottle 0.12.10 doesn"t filter a " " sequence, which leads to a CRLF attack, as demonstrated by a redirect("233 Set-Cookie: name=salt") call.
- Phase
- Assigned (20161216)
- Votes
- None (candidate not yet proposed)
- Comments