{"id":"CVE-2015-5285","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-5285","summary":"CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the came_from parameter to _admin/login.","details":"CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the came_from parameter to _admin/login.","published":"2015-10-29T20:59:04.553","modified":"2026-06-17T00:28:49.040","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":5,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/133897/Kallithea-0.2.9-HTTP-Response-Splitting.html"},{"type":"EXPLOIT","url":"http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5267.php"},{"type":"EXPLOIT","url":"https://kallithea-scm.org/security/cve-2015-5285.html"},{"type":"EXPLOIT","url":"https://www.exploit-db.com/exploits/38424/"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/133897/Kallithea-0.2.9-HTTP-Response-Splitting.html"},{"type":"EXPLOIT","url":"http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5267.php"},{"type":"EXPLOIT","url":"https://kallithea-scm.org/security/cve-2015-5285.html"},{"type":"EXPLOIT","url":"https://www.exploit-db.com/exploits/38424/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T00:28:49.040"}}