PT-2004-2381 · Snipsnap · Snipsnap
Maestro De-Seguridad
·
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-1470
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
SnipSnap versions 0.5.2a through 1.0b1
Description:
A CRLF injection issue allows remote attackers to perform HTTP Response Splitting attacks, modifying the expected HTML content from the server.
Recommendations:
For versions 0.5.2a through 1.0b1, update to version 1.0b1 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snipsnap