Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-1620. PoCs published by ChaoticEvil.
AI-analyzed exploit summary This exploit demonstrates an HTTP response splitting vulnerability in Serendipity 0.7-beta4 and prior. The attacker crafts a malicious URL with encoded headers to manipulate the HTTP response, potentially leading to cache poisoning or XSS.
Description
CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer field in comment.php.
Exploits (1)
This exploit demonstrates an HTTP response splitting vulnerability in Serendipity 0.7-beta4 and prior. The attacker crafts a malicious URL with encoded headers to manipulate the HTTP response, potentially leading to cache poisoning or XSS.