cve/2016/CVE-2016-10517.md
2024-06-09 00:33:16 +00:00

1007 B

CVE-2016-10517

Description

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

POC

Reference

Github

No PoCs found on GitHub currently.