Vulnerability Name: | CVE-2004-2054 (CCN-16759) | ||||||||
Assigned: | 2004-07-20 | ||||||||
Published: | 2004-07-20 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via (1) the mode parameter to privmsg.php or (2) the redirect parameter to login.php. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Jul 20 2004 - 01:21:19 CDT PhpBB HTTP Response Splitting & Cross Site Scripting vulnerabilities Source: MITRE Type: CNA CVE-2004-2054 Source: BUGTRAQ Type: UNKNOWN 20040720 PhpBB HTTP Response Splitting & Cross Site Scripting vulnerabilities Source: CCN Type: SA12114 phpBB Cross Site Scripting Vulnerabilities Source: SECUNIA Type: UNKNOWN 12114 Source: CCN Type: OSVDB ID: 59231 PhpBB privmsg.php mode Parameter HTTP Response Splitting Source: CCN Type: OSVDB ID: 59232 PhpBB login.php redirect Parameter HTTP Response Splitting Source: BID Type: Exploit 10753 Source: CCN Type: BID-10753 PHPBB Multiple HTTP Response Splitting Vulnerabilities Source: CCN Type: BID-10883 phpBB Login.PHP Cross-Site Scripting Vulnerability Source: XF Type: UNKNOWN phpbb-search-response-splitting(16759) Source: XF Type: UNKNOWN phpbb-search-response-splitting(16759) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |