Description
header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
Remediation
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2013-3735)
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2019-15226)
WordPress Plugin Travelpayouts:All Travel Brands in One Place Cross-Site Request Forgery (1.0.16)
MyBB Other Vulnerability (CVE-2007-0689)
Oracle Database Server CVE-2011-0880 Vulnerability (CVE-2011-0880)