5
CVSSv2

CVE-2006-5566

Published: 27/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in premium/index.php in Shop-Script allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the (1) links_exchange, (2) news, (3) search_with_change_category_ability, (4) logging, (5) feedback, (6) show_price, (7) register, (8) answer, (9) productID, and (10) inside parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

webasyst llc shop-script

Exploits

source: wwwsecurityfocuscom/bid/20685/info Shop-Script is prone to multiple HTTP response-splitting vulnerabilities because the application fails to properly sanitize user-supplied input A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached, or interpreted This could aid in var ...