Vulnerability CVE-2005-4830


Published: 2005-12-31   Modified: 2012-02-12

Description:
CRLF injection vulnerability in viewcvs in ViewCVS 0.9.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the content-type parameter.

Type:

CWE-Other

CVSS2 => (AV:N/AC:H/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.6/10
10/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Viewcvs -> Viewcvs 

 References:
http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030514.html
http://www.securityfocus.com/archive/1/461382/100/0/threaded
http://www.securityfocus.com/bid/12112

Copyright 2024, cxsecurity.com

 

Back to Top