CVE-2006-3105
Summary
| CVE | CVE-2006-3105 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-21 01:02:00 UTC |
| Updated | 2018-10-18 16:45:00 UTC |
| Description | CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in multiple unspecified parameters that are injected into HTTP headers, as demonstrated by the BWSESSION parameter in index.php. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| bitweaver download | SourceForge.net | CONFIRM | sourceforge.net | |
| SecurityReason - bitweaver <= v1.3 multiple vulnerabilities | SREASON | securityreason.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Error 404 :( | MISC | retrogod.altervista.org | Exploit |
| 26590 | OSVDB | www.osvdb.org | |
| bitweaver 1.3.1 is now available - bitweaver | CONFIRM | www.bitweaver.org | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.