20040901 ADVISORY: http response splitting hole in Comersus shopping cartmailing list
http://marc.info/?l=bugtraq&m=109405777905519&w=2 CVE-2004-1656
Comersus Cart 5.0 - HTTP Response Splitting
Record summary
CVE-2004-1656 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBComersus Cart 5.0 - HTTP Response SplittingExploitDB exploitby Maestro De-SeguridadNot analyzed1 file
References
411083vdb entry
http://www.securityfocus.com/bid/11083 comersus-cart-response-splitting(17201)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17201 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1656