5
CVSSv2

CVE-2004-1687

Published: 16/09/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote malicious users to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

snitz communications snitz forums 2000 3.0

snitz communications snitz forums 2000 3.4.03

snitz communications snitz forums 2000 3.4.04

snitz communications snitz forums 2000 3.3.01

snitz communications snitz forums 2000 3.3.02

snitz communications snitz forums 2000 3.3.03

snitz communications snitz forums 2000 3.4.02

snitz communications snitz forums 2000 3.1

snitz communications snitz forums 2000 3.3

Exploits

source: wwwsecurityfocuscom/bid/11201/info Snitz Forums is reported prone to a HTTP response splitting vulnerability The issue exists in a parameter of the 'downasp' script The issue presents itself due to a flaw in the affected script that allows an attacker to manipulate how GET requests are handled A remote attacker may exploit t ...