Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-3982. PoCs published by lwang.
AI-analyzed exploit summary The provided text describes an HTTP response-splitting vulnerability in WebCalendar 1.0.1, where unsanitized user input in the 'ret' parameter of 'layers_toggle.php' can be exploited to manipulate HTTP responses. This could facilitate attacks such as cache poisoning or phishing by redirecting users to malicious URLs.
Description
CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret parameter, which is used to redirect URL requests.
Exploits (1)
The provided text describes an HTTP response-splitting vulnerability in WebCalendar 1.0.1, where unsanitized user input in the 'ret' parameter of 'layers_toggle.php' can be exploited to manipulate HTTP responses. This could facilitate attacks such as cache poisoning or phishing by redirecting users to malicious URLs.