[Japanese] | |
JVNDB-2015-000142 | |
Apache Cordova plugin cordova-plugin-file-transfer vulnerable to HTTP header injection | |
Overview | |
cordova-plugin-file-transfer, a plugin for Apache Cordova provided by the Apache Software Foundation, provides functionality to upload and download files in applications created by Apache Cordova. It also provides functionality to add HTTP headers. | |
CVSS Severity (What is CVSS?) | |
CVSS V2 Severity:
Base Metrics 4.3 (Medium) [IPA Score]
| |
Affected Products | |
| |
Apache Software Foundation | |
| |
Impact | |
File name inclusion in additional HTTP headers may result in a forged webpage to be displayed on the user's web browser, arbitrary script execution, or setting arbitrary values for cookies. | |
Solution | |
[Update the plugin and rebuild the application] | |
Vendor Information | |
Apache Software Foundation | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2015/09/29 |
Date First Published | 2015/09/29 |
Date Last Updated | 2015/12/21 |