
Using the character %0A, it is possible to inject headers and content.įurthermore, this vulnerability allow us to exploit a session fixation

OpenVPN-AS (Version 2.1.4) is prone to CRLF injection. Internal network and/ or private cloud network resources andĪpplications with fine-grained access control. Range of configurations, including secure and granular remote access to OpenVPN Client software packages that accommodate Windows, MAC, Linux,Īndroid, and iOS environments. Software solution that integrates OpenVPN server capabilities,Įnterprise management capabilities, simplified OpenVPN Connect UI, and OpenVPN Access Server is a full featured secure network tunneling VPN

Change Mirror Download # OpenVPN Access Server : CRLF injection with Session fixation
