Информационная безопасность
[RU] switch to
English Version



CVECVE-2007-2047
СтатусCandidate
ОписаниеCRLF injection vulnerability in www/delivery/ck.php in Openads 2.3 (aka Max Media Manager, MMM) before 0.3.31-alpha-pr3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the destination parameter. NOTE: some of these details are obtained from third party information.
ВажностьHigh
CVSS score7
CVSS vector(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)
PhaseAssigned (16.04.2007)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2047
ReferencesCONFIRM : http://forum.openads.org/index.php?showtopic=50341...
 FRSIRT : ADV-2007-1365
SecurityVulns:Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server