Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2004-1620
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-1620

Description:
CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer field in comment.php.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/17798

ST
  1011864

SAID
  Secunia Advisory: SA12909

OSVDB
  11038
  11039
  11013

CONFIRM
  http://sourceforge.net/project/shownotes.php?release_id=276694
  http://cvs.sourceforge.net/viewcvs.py/php-blog/serendipity/exit.php?rev=1.10&view=markup
  http://cvs.sourceforge.net/viewcvs.py/php-blog/serendipity/index.php?rev=1.52&view=markup
  http://www.s9y.org/5.html
  http://cvs.sourceforge.net/viewcvs.py/php-blog/serendipity/comment.php?rev=1.49&view=markup

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=109841283115808&w=2

BID
  11497


Return to the previous page.