CVE-2010-4411
Last modified
CVE-2010-4411 is a vulnerability of currently unknown severity. Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOTE: this issue exists because of an incomplete fix for CVE-2010-2761.. EPSS estimates a 2.58% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOTE: this issue exists because of an incomplete fix for CVE-2010-2761.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Andy Armstrong | Cgi.Pm | <= 3.50 |
| Andy Armstrong | Cgi.Pm | 1.4 |
| Andy Armstrong | Cgi.Pm | 1.42 |
| Andy Armstrong | Cgi.Pm | 1.43 |
| Andy Armstrong | Cgi.Pm | 1.44 |
| Andy Armstrong | Cgi.Pm | 1.45 |
| Andy Armstrong | Cgi.Pm | 1.50 |
| Andy Armstrong | Cgi.Pm | 1.51 |
| Andy Armstrong | Cgi.Pm | 1.52 |
| Andy Armstrong | Cgi.Pm | 1.53 |
| Andy Armstrong | Cgi.Pm | 1.54 |
| Andy Armstrong | Cgi.Pm | 1.55 |
| Andy Armstrong | Cgi.Pm | 1.56 |
| Andy Armstrong | Cgi.Pm | 1.57 |
| Andy Armstrong | Cgi.Pm | 2.0 |
| Andy Armstrong | Cgi.Pm | 2.01 |
| Andy Armstrong | Cgi.Pm | 2.13 |
| Andy Armstrong | Cgi.Pm | 2.14 |
| Andy Armstrong | Cgi.Pm | 2.15 |
| Andy Armstrong | Cgi.Pm | 2.16 |
| Andy Armstrong | Cgi.Pm | 2.17 |
| Andy Armstrong | Cgi.Pm | 2.18 |
| Andy Armstrong | Cgi.Pm | 2.19 |
| Andy Armstrong | Cgi.Pm | 2.20 |
| Andy Armstrong | Cgi.Pm | 2.21 |
| Andy Armstrong | Cgi.Pm | 2.22 |
| Andy Armstrong | Cgi.Pm | 2.23 |
| Andy Armstrong | Cgi.Pm | 2.24 |
| Andy Armstrong | Cgi.Pm | 2.25 |
| Andy Armstrong | Cgi.Pm | 2.26 |
| Andy Armstrong | Cgi.Pm | 2.27 |
| Andy Armstrong | Cgi.Pm | 2.28 |
| Andy Armstrong | Cgi.Pm | 2.29 |
| Andy Armstrong | Cgi.Pm | 2.30 |
| Andy Armstrong | Cgi.Pm | 2.31 |
| Andy Armstrong | Cgi.Pm | 2.32 |
| Andy Armstrong | Cgi.Pm | 2.33 |
| Andy Armstrong | Cgi.Pm | 2.34 |
| Andy Armstrong | Cgi.Pm | 2.35 |
| Andy Armstrong | Cgi.Pm | 2.36 |
| Andy Armstrong | Cgi.Pm | 2.37 |
| Andy Armstrong | Cgi.Pm | 2.38 |
| Andy Armstrong | Cgi.Pm | 2.39 |
| Andy Armstrong | Cgi.Pm | 2.40 |
| Andy Armstrong | Cgi.Pm | 2.41 |
| Andy Armstrong | Cgi.Pm | 2.42 |
| Andy Armstrong | Cgi.Pm | 2.43 |
| Andy Armstrong | Cgi.Pm | 2.44 |
| Andy Armstrong | Cgi.Pm | 2.45 |
| Andy Armstrong | Cgi.Pm | 2.46 |
Showing 50 of 155 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-4411?
How severe is CVE-2010-4411?
How do I fix CVE-2010-4411?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-4405Cross-site scripting (XSS) vulnerability in the Yannick Gaul…
- CVE-2010-4406Directory traversal vulnerability in gallery.php in Brunetto…
- CVE-2010-4407Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2010-4408Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 thr…
- CVE-2010-4409Integer overflow in the NumberFormatter::getSymbol (aka numf…
- CVE-2010-4410CRLF injection vulnerability in the header function in (1) C…
- CVE-2010-4412Multiple cross-site scripting (XSS) vulnerabilities in pfSen…
- CVE-2010-4413Unspecified vulnerability in the Scheduler Agent component i…
- CVE-2010-4414Unspecified vulnerability in Oracle VM VirtualBox 4.0 allows…
- CVE-2010-4415Unspecified vulnerability in Oracle Solaris 8, 9, and 10 all…
- CVE-2010-4416Unspecified vulnerability in the Oracle GoldenGate Veridata …
- CVE-2010-4417Unspecified vulnerability in the Services for Beehive compon…
Are you affected by CVE-2010-4411?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
