Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Maestro

#49598of 53,624
5Total CVSS
Vulnerabilities · 1
PT-2004-2562
5.0
2004-09-01
Comersus · Comersus Shopping Cart · CVE-2004-1656
**Name of the Vulnerable Software and Affected Versions** Comersus Shopping Cart version 5.0991 **Description** A CRLF injection issue allows remote attackers to perform HTTP Response Splitting attacks, modifying expected HTML content from the server via the `redirecturl` parameter. **Recommendations** For Comersus Shopping Cart version 5.0991, avoid using the `redirecturl` parameter in affected API endpoints until the issue is resolved. Consider restricting access to this parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.