Description
header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gallery-Photo Albums-Portfolio Cross-Site Scripting (1.3.47)
WordPress Plugin Error Log Monitor Security Bypass (1.6.4)
MediaWiki Improper Input Validation Vulnerability (CVE-2017-0368)
SharePoint Download of Code Without Integrity Check Vulnerability (CVE-2020-1452)
WordPress Plugin Backup Migration Information Disclosure (1.3.5)