Vulnerabilities > CVE-2004-1516 - Unspecified vulnerability in PHPwebsite
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN phpwebsite
nessus
Summary
CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the block_username parameter in the user module.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 8 |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200411-35.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200411-35 (phpWebSite: HTTP response splitting vulnerability) Due to lack of proper input validation, phpWebSite has been found to be vulnerable to HTTP response splitting attacks. Impact : A malicious user could inject arbitrary response data, leading to content spoofing, web cache poisoning and other cross-site scripting or HTTP response splitting attacks. This could result in compromising the victim |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15837 |
published | 2004-11-27 |
reporter | This script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/15837 |
title | GLSA-200411-35 : phpWebSite: HTTP response splitting vulnerability |
code |
|
References
- http://marc.info/?l=bugtraq&m=110022027420583&w=2
- http://marc.info/?l=bugtraq&m=110022027420583&w=2
- http://phpwebsite.appstate.edu/index.php?module=announce&ANN_id=863&ANN_user_op=view
- http://phpwebsite.appstate.edu/index.php?module=announce&ANN_id=863&ANN_user_op=view
- http://secunia.com/advisories/13172/
- http://secunia.com/advisories/13172/
- http://security.gentoo.org/glsa/glsa-200411-35.xml
- http://security.gentoo.org/glsa/glsa-200411-35.xml
- http://www.securityfocus.com/bid/11673
- http://www.securityfocus.com/bid/11673
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18046
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18046