5
CVE-2006-3105
- EPSS 2.63%
- Veröffentlicht 21.06.2006 01:02:00
- Zuletzt bearbeitet 16.06.2026 22:26:24
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in multiple unspecified parameters that are injected into HTTP headers, as demonstrated by the BWSESSION parameter in index.php.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.63% | 0.835 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://retrogod.altervista.org/bitweaver_13_xpl.html
http://securityreason.com/securityalert/1115
http://sourceforge.net/project/shownotes.php?release_id=336854&group_id=141358
http://www.bitweaver.org/articles/45
http://www.securityfocus.com/archive/1/437491/100/0/threaded
http://www.osvdb.org/26590
https://exchange.xforce.ibmcloud.com/vulnerabilities/27348