CVE-2004-2512 Information

Description

CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web caches via CRLF (\0d0a) sequences in the PHPSESSID parameter.

Reference

http://archives.neohapsis.com/archives/bugtraq/2004-10/0042.html http://secunia.com/advisories/12751 http://securitytracker.com/id?1011481 http://www.osvdb.org/10591 http://www.securityfocus.com/bid/11340 https://exchange.xforce.ibmcloud.com/vulnerabilities/17640

Share on: