CVE-2006-5330
Last modified
CVE-2006-5330 is a vulnerability of currently unknown severity. CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks via CRLF sequences in arguments to the ActionScript functions (1) XML.addRequestHeader and (2) XML.contentType. NOTE: the flexibility of the attack varies depending on the type of web browser being used.. EPSS estimates a 22.60% chance of exploitation in the next 30 days.
Description
CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks via CRLF sequences in arguments to the ActionScript functions (1) XML.addRequestHeader and (2) XML.contentType. NOTE: the flexibility of the attack varies depending on the type of web browser being used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Flash Player | <= 7.0.63 |
| Adobe | Flash Player | <= 7.0_r67 |
| Adobe | Flash Player | <= 9.0.16 |
| Adobe | Flash Player | <= 9.0.28.0 |
References
- http://secunia.com/advisories/22467Vendor Advisory
- http://secunia.com/advisories/23324Vendor Advisory
- http://secunia.com/advisories/23581Vendor Advisory
- http://secunia.com/advisories/24479Vendor Advisory
- http://secunia.com/advisories/25467Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlUS Government Resource
- http://secunia.com/advisories/22467Vendor Advisory
- http://secunia.com/advisories/23324Vendor Advisory
- http://secunia.com/advisories/23581Vendor Advisory
- http://secunia.com/advisories/24479Vendor Advisory
- http://secunia.com/advisories/25467Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-5330?
How severe is CVE-2006-5330?
How do I fix CVE-2006-5330?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-5324The Web Services Notification (WSN) security component of IB…
- CVE-2006-5325Multiple PHP remote file inclusion vulnerabilities in Dimitr…
- CVE-2006-5326PHP remote file inclusion vulnerability in language/lang/lan…
- CVE-2006-5327Untrusted search path vulnerability in OpenBase SQL 10.0 and…
- CVE-2006-5328OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.…
- CVE-2006-5329Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2006-5331The altivec_unavailable_exception function in arch/powerpc/k…
- CVE-2006-5332Unspecified vulnerability in xdb.dbms_xdbz in the XMLDB comp…
- CVE-2006-5333Unspecified vulnerability in Oracle Spatial component in Ora…
- CVE-2006-5334Unspecified vulnerability in Oracle Spatial component in Ora…
- CVE-2006-5335Multiple unspecified vulnerabilities in Oracle Database 10.1…
- CVE-2006-5336Multiple unspecified vulnerabilities in the Change Data Capt…
Are you affected by CVE-2006-5330?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
