5
CVSSv2

CVE-2004-1564

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote malicious users to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

w-agora w-agora 4.1.6a

Exploits

source: wwwsecurityfocuscom/bid/11283/info Multiple vulnerabilities are reported to affect the application These issues arise due to insufficient sanitization of user-supplied data A remote attacker may leverage these vulnerabilities to carry out SQL injection, cross-site scripting, and HTTP response splitting attacks These issues ...