CVE-2013-2652

WebCollab <3.30 - HTTP Response Splitting

Title source: llm

Description

CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the item parameter.

Scores

EPSS 0.0050
EPSS Percentile 65.6%

Details

CWE
CWE-79
Status published
Products (38)
andrew_simpson/webcollab < 3.30
andrew_simpson/webcollab
andrew_simpson/webcollab
andrew_simpson/webcollab
andrew_simpson/webcollab
andrew_simpson/webcollab
andrew_simpson/webcollab
andrew_simpson/webcollab
andrew_simpson/webcollab
andrew_simpson/webcollab
... and 28 more
Published Nov 02, 2013
Tracked Since Feb 18, 2026