CVE-2004-1564

Properties

Published:
30.12.2004
Updated:
20.10.2005
Patch available:
Severity:
Low
  • CVSS vector:
    (AV:R/AC:L/Au:NR/C:N/I:C/A:N/B:N) Approximated
    Product:
    W-Agora: W-Agora

    Vulnerability description

    CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter.

    References:

    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109655691512298&w=2
    FULLDISC: http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html
    BID: http://www.securityfocus.com/bid/11283
    SECUNIA: http://secunia.com/advisories/12695
    XF: http://xforce.iss.net/xforce/xfdb/17558
    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109655691512298&w=2
    SECTRACK: http://securitytracker.com/id?1011463