4.3
CVSSv2

CVE-2004-2512

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and previous versions allows remote malicious users to conduct HTTP response splitting attacks to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the PHPSESSID parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

codeworx technologies dcp-portal 5.0.2

codeworx technologies dcp-portal 5.1

codeworx technologies dcp-portal 3.7

codeworx technologies dcp-portal 4.0

codeworx technologies dcp-portal 4.1

codeworx technologies dcp-portal 4.2

codeworx technologies dcp-portal 5.3.1

codeworx technologies dcp-portal

codeworx technologies dcp-portal 5.2

codeworx technologies dcp-portal 5.3

codeworx technologies dcp-portal 4.5.1

codeworx technologies dcp-portal 5.0.1

Exploits

source: wwwsecurityfocuscom/bid/11340/info DCP-Portal is reported prone to a HTTP response splitting vulnerability The issue presents itself due to a flaw in the affected script that allows an attacker to manipulate how GET requests are handled A remote attacker may exploit this vulnerability to influence or misrepresent how web conten ...