peter bassill · operator
$ cve CVE-2008-3906 JSON

CVE-2008-3906 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 7.1% (pctl 94)

Patch early

A public exploit exists.

Description

CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS7.1% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2008-09-04
Last modified2026-06-16

Affected (2)

VendorProduct
monomono
mono projectmono

Public exploits

SourceTitleDate
exploit-dbMono 2.0 - 'System.Web' HTTP Header Injection2008-08-20

References

→ the Explorer  ·  watch your stack  ·  NVD