Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-1470. PoCs published by Maestro De-Seguridad.
AI-analyzed exploit summary This exploit demonstrates an HTTP response splitting vulnerability in SnipSnap by injecting malicious headers via the 'referer' parameter. The PoC manipulates the server's response to include arbitrary content, potentially leading to cache poisoning or XSS attacks.
Description
CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server.
Exploits (1)
This exploit demonstrates an HTTP response splitting vulnerability in SnipSnap by injecting malicious headers via the 'referer' parameter. The PoC manipulates the server's response to include arbitrary content, potentially leading to cache poisoning or XSS attacks.