Description
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
Remediation
References
Related Vulnerabilities
WordPress Plugin LionScripts:IP Blocker Lite Cross-Site Request Forgery (10.3)
WordPress Plugin iThemes Security (formerly Better WP Security) Information Disclosure (5.1.1)
MySQL CVE-2021-2081 Vulnerability (CVE-2021-2081)
WordPress Plugin PHP Everywhere Multiple Remote Code Execution Vulnerabilities (2.0.3)