5
CVSSv2

CVE-2011-4545

Published: 02/12/2011 Updated: 13/12/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the name parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

prestashop prestashop 1.4.4.1

Exploits

source: wwwsecurityfocuscom/bid/50785/info Prestashop is prone to an HTTP-response-splitting vulnerability because it fails to sufficiently sanitize user-supplied data Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted This could aid various attacks that try to entice client ...