{"api_version":"1","generated_at":"2026-07-23T06:03:57+00:00","cve":"CVE-2004-1513","urls":{"html":"https://cve.report/CVE-2004-1513","api":"https://cve.report/api/cve/CVE-2004-1513.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1513","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1513"},"summary":{"title":"CVE-2004-1513","description":"04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=110012542615484&w=2","name":"http://marc.info/?l=bugtraq&m=110012542615484&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/13159/","name":"http://secunia.com/advisories/13159/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - 04WebServer Three Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.soft3304.net/04WebServer/Security.html","name":"http://www.soft3304.net/04WebServer/Security.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=110054395311823&w=2","name":"http://marc.info/?l=bugtraq&m=110054395311823&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/11652","name":"http://www.securityfocus.com/bid/11652","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"04WebServer Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18034","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18034","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.security.org.sg/vuln/04webserver142.html","name":"http://www.security.org.sg/vuln/04webserver142.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Security in Real Estate Property – Property Management","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1513","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1513","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1513","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"soft3304","cpe5":"04webserver","cpe6":"1.42","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:53:24.069Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"11652","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11652"},{"name":"20041110 04WebServer Three Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=110012542615484&w=2"},{"name":"04webserver-web-log-spoofing(18034)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18034"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.soft3304.net/04WebServer/Security.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.security.org.sg/vuln/04webserver142.html"},{"name":"20041115 Re: 04WebServer Three Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=110054395311823&w=2"},{"name":"13159","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/13159/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-11-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"11652","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11652"},{"name":"20041110 04WebServer Three Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=110012542615484&w=2"},{"name":"04webserver-web-log-spoofing(18034)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18034"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.soft3304.net/04WebServer/Security.html"},{"tags":["x_refsource_MISC"],"url":"http://www.security.org.sg/vuln/04webserver142.html"},{"name":"20041115 Re: 04WebServer Three Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=110054395311823&w=2"},{"name":"13159","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/13159/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1513","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"11652","refsource":"BID","url":"http://www.securityfocus.com/bid/11652"},{"name":"20041110 04WebServer Three Vulnerabilities","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=110012542615484&w=2"},{"name":"04webserver-web-log-spoofing(18034)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18034"},{"name":"http://www.soft3304.net/04WebServer/Security.html","refsource":"CONFIRM","url":"http://www.soft3304.net/04WebServer/Security.html"},{"name":"http://www.security.org.sg/vuln/04webserver142.html","refsource":"MISC","url":"http://www.security.org.sg/vuln/04webserver142.html"},{"name":"20041115 Re: 04WebServer Three Vulnerabilities","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=110054395311823&w=2"},{"name":"13159","refsource":"SECUNIA","url":"http://secunia.com/advisories/13159/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1513","datePublished":"2005-02-19T05:00:00.000Z","dateReserved":"2005-02-18T00:00:00.000Z","dateUpdated":"2024-08-08T00:53:24.069Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:soft3304:04webserver:1.42:*:*:*:*:*:*:*","matchCriteriaId":"B6068B76-8085-4942-9872-D69E82AF9D19"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1513","Ordinal":"1","Title":"CVE-2004-1513","CVE":"CVE-2004-1513","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1513","Ordinal":"1","NoteData":"04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries.","Type":"Description","Title":"CVE-2004-1513"},{"CveYear":"2004","CveId":"1513","Ordinal":"2","NoteData":"2005-02-19","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1513","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}