Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-1951. PoCs published by GulfTech Security.
AI-analyzed exploit summary The provided text describes HTTP response splitting vulnerabilities in osCommerce due to improper input sanitization. It includes example URLs demonstrating how an attacker could inject malicious headers.
Description
Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the (1) products_id or (2) pid parameter to index.php or (3) goto parameter to banner.php.
Exploits (1)
The provided text describes HTTP response splitting vulnerabilities in osCommerce due to improper input sanitization. It includes example URLs demonstrating how an attacker could inject malicious headers.