20040914 ADVISORY: http response splitting in snipsnapmailing list
http://marc.info/?l=bugtraq&m=109518773223511&w=2 CVE-2004-1470
SnipSnap 0.5.2 - HTTP Response Splitting
Record summary
CVE-2004-1470 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSnipSnap 0.5.2 - HTTP Response SplittingExploitDB exploitby Maestro De-SeguridadNot analyzed1 file
References
6GLSA-200409-23Vendor advisory
http://www.gentoo.org/security/en/glsa/glsa-200409-23.xml 11180vdb entry
http://www.securityfocus.com/bid/11180 snipsnap.orgConfirmation
http://www.snipsnap.org/space/start snipsnap-response-splitting(17364)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17364 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1470