5
CVSSv2

CVE-2005-3982

Published: 04/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote malicious users to modify HTTP headers and conduct HTTP response splitting attacks via the ret parameter, which is used to redirect URL requests.

Vulnerable Product Search on Vulmon Subscribe to Product

webcalendar webcalendar 1.0.1

Exploits

source: wwwsecurityfocuscom/bid/15673/info WebCalendar is prone to an HTTP response-splitting vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached, or interpreted This coul ...