PT-2004-2381 · Snipsnap · Snipsnap

Maestro De-Seguridad

·

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-1470

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: SnipSnap versions 0.5.2a through 1.0b1
Description: A CRLF injection issue allows remote attackers to perform HTTP Response Splitting attacks, modifying the expected HTML content from the server.
Recommendations: For versions 0.5.2a through 1.0b1, update to version 1.0b1 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1470

Affected Products

Snipsnap