tracker issue : CF-3041850

select a category, or use search below
(searches all categories and all time range)
Title:

Bug 83739:Any tag that writes a header, for example cfheader, cfcontent, cfmail, cfmailpart, cfmailparam should not allow CRLF characters because that allows the creation of an additional header

| View in Tracker

Status/Resolution/Reason: Closed/Fixed/

Reporter/Name(from Bugbase): Peter Freitag / Peter Freitag (Peter Freitag)

Created: 08/02/2010

Components: Language, Tags

Versions: 9.0

Failure Type: Unspecified

Found In Build/Fixed In Build: 0000 / 276482

Priority/Frequency: Normal / Unknown

Locale/System: English / Platforms All

Vote Count: 12

Problem:

Any tag that writes a header, for example cfheader, cfcontent, cfmail, cfmailpart, cfmailparam should not allow CRLF characters because that allows the creation of an additional header. There should not be any reason for these tags to create subheaders. One especially important place to fix this is in the subject attribute of cfmail. 
Method:

example.cfm?type=html%0D%0ARefresh:0;url=http://foundeo.comexample.cfm:<cfheader name="Content-Type" value="text/#url.type#">
Result:

Strip CRLF from tags that write protocol headers to prevent CRLF injection.

----------------------------- Additional Watson Details -----------------------------

Watson Bug ID:	3041850

External Customer Info:
External Company:  
External Customer Name: Peter Freitag
External Customer Email: 735D4A6E43D50B6B992016B8
External Test Config: 08/02/2010

Attachments:

Comments:

This bug has been voted..
Vote by External U.
21536 | November 11, 2011 12:51:48 AM GMT
This bug has been voted..
Vote by External U.
21537 | November 11, 2011 12:51:49 AM GMT
This bug has been voted..
Vote by External U.
21538 | November 11, 2011 12:51:51 AM GMT
This bug has been voted..
Vote by External U.
21539 | November 11, 2011 12:51:52 AM GMT
This bug has been voted..
Vote by External U.
21540 | November 11, 2011 12:51:54 AM GMT
This bug has been voted..
Vote by External U.
21541 | November 11, 2011 12:51:55 AM GMT
This bug has been voted..
Vote by External U.
21542 | November 11, 2011 12:51:57 AM GMT
This bug has been voted..
Vote by External U.
21543 | November 11, 2011 12:51:58 AM GMT
This bug has been voted..
Vote by External U.
21544 | November 11, 2011 12:52:00 AM GMT
This bug has been voted..
Vote by External U.
21545 | November 11, 2011 12:52:02 AM GMT
This bug has been voted..
Vote by External U.
21546 | November 11, 2011 12:52:04 AM GMT
This bug has been voted..
Vote by External U.
21547 | November 11, 2011 12:52:06 AM GMT