Vulnerability Name: | CVE-2007-4190 (CCN-35688) | ||||||||
Assigned: | 2007-07-24 | ||||||||
Published: | 2007-07-24 | ||||||||
Updated: | 2021-10-01 | ||||||||
Summary: | CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in the url parameter. Note: this can be leveraged for cross-site scripting (XSS) attacks. Note: some of these details are obtained from third party information. | ||||||||
CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-74 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-4190 Source: OSVDB Type: Broken Link 38739 Source: CCN Type: SA26239 Joomla! Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 26239 Source: CCN Type: Joomla Web site: 1.0.13 Changelog SECURITY A6 [LOW Level]: Fixed [#5630] HRS attack on variable "url" Source: MISC Type: Vendor Advisory http://www.joomla.org/content/view/3677/1/ Source: CCN Type: OSVDB ID: 38739 Joomla! url Parameter CRLF Injection Source: CCN Type: BID-25122 Joomla! 1.0.12 Multiple Security Vulnerabilities Source: VUPEN Type: Third Party Advisory ADV-2007-2719 Source: XF Type: UNKNOWN joomla-url-response-splitting(35688) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |