CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter.
References
Link | Resource |
---|---|
http://forum.snitz.com/forum/topic.asp?ARCHIVE=true&TOPIC_ID=54791 | Vendor Advisory |
http://www.securityfocus.com/bid/11201 | Exploit Patch Vendor Advisory |
http://secunia.com/advisories/12590 | Patch Vendor Advisory |
http://marc.info/?l=bugtraq&m=109537195413691&w=2 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17421 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2004-09-15 21:00
Updated : 2017-07-10 18:31
NVD link : CVE-2004-1687
Mitre link : CVE-2004-1687
JSON object : View
CWE
Products Affected
snitz_communications
- snitz_forums_2000