CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/17558 | vdb entry |
http://securitytracker.com/id?1011463 | vdb entry |
http://secunia.com/advisories/12695 | third party advisory patch vendor advisory |
http://www.securityfocus.com/bid/11283 | vdb entry exploit |
http://marc.info/?l=bugtraq&m=109655691512298&w=2 | mailing list |
http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html | mailing list exploit vendor advisory |