Description
Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.
Remediation
References
Related Vulnerabilities
Family Connections Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-4338)
WordPress Plugin WordPress Infinite Scroll-Ajax Load More Unspecified Vulnerability (2.11.0)
WordPress Plugin WP-Recall-Registration, Profile, Commerce & More Security Bypass (16.26.6)
WordPress Plugin wp-buddha-free-adwords Security Bypass (1.0.0)