20041006 HTTP Response Splitting Vulnerability in Wordpress 1.2mailing list
http://marc.info/?l=bugtraq&m=109716327724041&w=2 CVE-2004-1584
WordPress Core 1.2 - HTTP Splitting
Record summary
CVE-2004-1584 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Core 1.2 - HTTP SplittingExploitDB exploitby Tenable NSNot analyzed1 file
References
712773Third-party advisory
http://secunia.com/advisories/12773 wordpress.orgConfirmation
http://wordpress.org/development/2004/10/wp-121 GLSA-200410-12Vendor advisory
http://www.gentoo.org/security/en/glsa/glsa-200410-12.xml 11348vdb entry
http://www.securityfocus.com/bid/11348 wordpress-response-splitting(17649)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17649 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1584