HTTP Response Splitting vulnerability in the Surveys module in PHP-Nuke 7.6 allows remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the forwarder parameter.
Link | Tags |
---|---|
http://www.digitalparadox.org/advisories/pnuke.txt | exploit vendor advisory |
http://www.osvdb.org/15647 | vdb entry |
http://secunia.com/advisories/14965 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/20116 | vdb entry |
http://marc.info/?l=bugtraq&m=111359804013536&w=2 | mailing list |