HTTP: Response Splitting in HTTP Variable
This signature detects HTTP requests with encoded characters that are consistent with an HTTP response splitting attack. Attackers can execute script code on the target's browser or poison an HTTP cache server. Note: Some Web applications might use these characters legitimately.
Extended Description
Use of HTTP response splitting could enable a remote attacker to launch a cross-site scripting attack, poison a server's or a browser's cache, deface a web page, or hijack user information.
References
URL: http://www.sanctuminc.com/pdf/Whitepaper_HTTPResponse.pdf
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3