peter bassill · operator
$ cve CVE-2006-1039 JSON

CVE-2006-1039 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 2.7% (pctl 86)

Patch early

A public exploit exists.

Description

SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS2.74% — more likely to be exploited than 86% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2006-03-07
Last modified2026-06-16

Affected (1)

VendorProduct
sapsap web application server

Public exploits

SourceTitleDate
exploit-dbSAP Web Application Server 6.x/7.0 - Input Validation2005-11-09

References

→ the Explorer  ·  watch your stack  ·  NVD