CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter.
References
Configurations
Information
Published : 2008-01-09 16:46
Updated : 2018-10-15 14:58
NVD link : CVE-2008-0202
Mitre link : CVE-2008-0202
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
expressionengine
- expressionengine