CVE Database · CVE-2006-1039
CVSS v3.1
N/A
EPSS
2.74%
Published
Mar 7, 2006
Modified
Jun 16, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers.
Weaknesses (CWE)
Affected Products (3)
References (12)