CVE

Id
96784  
CVE No.
CVE-2016-9964  
Status
Candidate  
Description
redirect() in bottle.py in bottle 0.12.10 doesn"t filter a " " sequence, which leads to a CRLF attack, as demonstrated by a redirect("233 Set-Cookie: name=salt") call.  
Phase
Assigned (20161216)  
Votes
None (candidate not yet proposed)  
Comments