CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via (1) the mode parameter to privmsg.php or (2) the redirect parameter to login.php.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=109034476122723&w=2 - | |
References | () http://secunia.com/advisories/12114 - | |
References | () http://www.securityfocus.com/bid/10753 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/16759 - |
Information
Published : 2004-12-31 05:00
Updated : 2024-11-20 23:52
NVD link : CVE-2004-2054
Mitre link : CVE-2004-2054
CVE.ORG link : CVE-2004-2054
JSON object : View
Products Affected
phpbb_group
- phpbb
CWE