Vulnerabilities > CVE-2004-1470 - Unspecified vulnerability in Snipsnap 0.5.2A
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | SnipSnap 0.5.2 HTTP Response Splitting Vulnerability. CVE-2004-1470. Remote exploits for multiple platform |
id | EDB-ID:24598 |
last seen | 2016-02-02 |
modified | 2004-09-14 |
published | 2004-09-14 |
reporter | Maestro De-Seguridad |
source | https://www.exploit-db.com/download/24598/ |
title | SnipSnap 0.5.2 HTTP Response Splitting Vulnerability |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200409-23.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200409-23 (SnipSnap: HTTP response splitting) SnipSnap contains various HTTP response splitting vulnerabilities that could potentially compromise the sites data. Some of these attacks include web cache poisoning, cross-user defacement, hijacking pages with sensitive user information, and cross-site scripting. This vulnerability is due to the lack of illegal input checking in the software. Impact : A malicious user could inject and execute arbitrary script code, potentially compromising the victim |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14774 |
published | 2004-09-17 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/14774 |
title | GLSA-200409-23 : SnipSnap: HTTP response splitting |
code |
|
References
- http://marc.info/?l=bugtraq&m=109518773223511&w=2
- http://marc.info/?l=bugtraq&m=109518773223511&w=2
- http://www.gentoo.org/security/en/glsa/glsa-200409-23.xml
- http://www.gentoo.org/security/en/glsa/glsa-200409-23.xml
- http://www.securityfocus.com/bid/11180
- http://www.securityfocus.com/bid/11180
- http://www.snipsnap.org/space/start
- http://www.snipsnap.org/space/start
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17364
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17364