AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2011-1895

MEDIUM · CVSS 4.3 EPSS 11.14%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2011-10-12 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2011-1895
Severity
MEDIUM
CVSS
4.3
EPSS
11.14%
Microsoft

Original NVD Description

CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via unspecified vectors, aka "ExcelTable Response Splitting XSS Vulnerability."