Vulnerability Name: | CVE-2005-3621 (CCN-23198) | ||||||||||||
Assigned: | 2005-11-16 | ||||||||||||
Published: | 2005-11-16 | ||||||||||||
Updated: | 2008-09-05 | ||||||||||||
Summary: | CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attackers to conduct HTTP response splitting attacks via unspecified scripts. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Nov 15 2005 - 05:53:50 CST Multiple Vulnerabilities in phpMyAdmin Source: MITRE Type: CNA CVE-2005-3621 Source: CCN Type: SA17578 phpMyAdmin HTTP Response Splitting and Cross-Site Scripting Source: SECUNIA Type: UNKNOWN 17578 Source: SECUNIA Type: UNKNOWN 22781 Source: CCN Type: SECTRACK ID: 1015213 phpMyAdmin `libraries/header_http.inc.php` Lets Remote Users Conduct HTTP Response Splitting Attacks Source: SECTRACK Type: UNKNOWN 1015213 Source: DEBIAN Type: UNKNOWN DSA-1207 Source: DEBIAN Type: DSA-1207 phpmyadmin -- several vulnerabilities Source: SUSE Type: UNKNOWN SUSE-SR:2005:028 Source: CCN Type: OSVDB ID: 20910 phpMyAdmin header_http.inc.php HTTP Response Splitting Source: CCN Type: phpMyAdmin Web site phpMyAdmin | MySQL Database Administration Tool | www.phpmyadmin.net Source: CONFIRM Type: Patch, Vendor Advisory http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-6 Source: CCN Type: BID-15422 PHPMyAdmin Header_HTTP_Inc.PHP HTTP Response Splitting Vulnerability Source: XF Type: UNKNOWN phpmyadmin-headerhttpinc-response-splitting(23198) Source: SUSE Type: SUSE-SR:2005:028 SUSE Security Summary Report | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |