Vulnerabilities > CVE-2004-2512 - Unspecified vulnerability in Codeworx Technologies Dcp-Portal
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the PHPSESSID parameter.
Vulnerable Configurations
Exploit-Db
description | DCP-Portal 3.7/4.x/5.x Calendar.PHP HTTP Response Splitting Vulnerability. CVE-2004-2512. Webapps exploit for php platform |
id | EDB-ID:24665 |
last seen | 2016-02-02 |
modified | 2004-10-06 |
published | 2004-10-06 |
reporter | Alexander Antipov |
source | https://www.exploit-db.com/download/24665/ |
title | DCP-Portal 3.7/4.x/5.x Calendar.PHP HTTP Response Splitting Vulnerability |
Nessus
NASL family | CGI abuses : XSS |
NASL id | DCP_PORTAL_XSS.NASL |
description | The version of DCP-Portal installed on the remote host fails to sanitize input to the script |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11446 |
published | 2003-03-23 |
reporter | This script is Copyright (C) 2003-2018 k-otik.com & Copyright (C) 2004-2014 David Maciejak |
source | https://www.tenable.com/plugins/nessus/11446 |
title | DCP-Portal Multiple Script XSS |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2004-10/0042.html
- http://archives.neohapsis.com/archives/bugtraq/2004-10/0042.html
- http://secunia.com/advisories/12751
- http://secunia.com/advisories/12751
- http://securitytracker.com/id?1011481
- http://securitytracker.com/id?1011481
- http://www.osvdb.org/10591
- http://www.osvdb.org/10591
- http://www.securityfocus.com/bid/11340
- http://www.securityfocus.com/bid/11340
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17640
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17640