Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-27780
Description:The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe parser and get transposed into `http://example.com/127.0.0.1/`. This flawcan be used to circumvent filters, checks and more.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-27780
https://security.gentoo.org/glsa/202212-01
https://hackerone.com/reports/1553841
https://hackerone.com/reports/1553841




© 1998-2025 E-Soft Inc. All rights reserved.