7.5
CVE-2007-0892
- EPSS 0.75%
- Veröffentlicht 12.02.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
CRLF injection vulnerability in phpMyVisites before 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the url parameter, when the pagename parameter begins with "FILE:".
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Matthieu Aubry ≫ Phpmyvisites Version <= 2.1
Matthieu Aubry ≫ Phpmyvisites Version0.1_beta
Matthieu Aubry ≫ Phpmyvisites Version1.0
Matthieu Aubry ≫ Phpmyvisites Version1.1
Matthieu Aubry ≫ Phpmyvisites Version1.2
Matthieu Aubry ≫ Phpmyvisites Version1.2.1
Matthieu Aubry ≫ Phpmyvisites Version1.2.2
Matthieu Aubry ≫ Phpmyvisites Version1.2_beta
Matthieu Aubry ≫ Phpmyvisites Version1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.75% | 0.725 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.