CVE-2004-1564
w-agora 4.1.6a - HTTP Response Splitting via Thread Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1564. PoCs published by Alexander Antipov.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in W-Agora 4.1.6a, including SQL injection, XSS, and HTTP response splitting due to insufficient input sanitization. It references a specific endpoint but does not include functional exploit code.
Description
CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter.
Exploits (1)
The provided text describes multiple vulnerabilities in W-Agora 4.1.6a, including SQL injection, XSS, and HTTP response splitting due to insufficient input sanitization. It references a specific endpoint but does not include functional exploit code.