CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/17364 | vdb entry |
http://www.securityfocus.com/bid/11180 | patch vdb entry exploit |
http://www.gentoo.org/security/en/glsa/glsa-200409-23.xml | patch vendor advisory |
http://marc.info/?l=bugtraq&m=109518773223511&w=2 | mailing list |
http://www.snipsnap.org/space/start |