UBBCentral UBB.Threads Multiple HTTP Response Splitting Vulnerabilities
BID:14053
Info
UBBCentral UBB.Threads Multiple HTTP Response Splitting Vulnerabilities
| Bugtraq ID: | 14053 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 24 2005 12:00AM |
| Updated: | Jun 24 2005 12:00AM |
| Credit: | James Bercegay of the GulfTech Security Research Team is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
UBBCentral UBB.threads 6.5.1 .1 UBBCentral UBB.threads 6.5.1 UBBCentral UBB.threads 6.5 UBBCentral UBB.threads 6.2.3 UBBCentral UBB.threads 6.0 |
| Not Vulnerable: |
UBBCentral UBB.threads 6.5.2 Beta2 |
Discussion
UBBCentral UBB.Threads Multiple HTTP Response Splitting Vulnerabilities
UBB.Threads is prone to multiple HTTP response splitting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
A remote attacker may exploit any of these vulnerabilities to influence or misrepresent how Web content is served, cached or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.
UBB.Threads is prone to multiple HTTP response splitting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
A remote attacker may exploit any of these vulnerabilities to influence or misrepresent how Web content is served, cached or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.
Exploit / POC
UBBCentral UBB.Threads Multiple HTTP Response Splitting Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
UBBCentral UBB.Threads Multiple HTTP Response Splitting Vulnerabilities
Solution:
The vendor has addressed this issue in UBB.Threads version 6.5.2beta2:
UBBCentral UBB.threads 6.0
UBBCentral UBB.threads 6.2.3
UBBCentral UBB.threads 6.5
UBBCentral UBB.threads 6.5.1
UBBCentral UBB.threads 6.5.1 .1
Solution:
The vendor has addressed this issue in UBB.Threads version 6.5.2beta2:
UBBCentral UBB.threads 6.0
-
UBBCentral UBB.Threads 6.5.2beta2
http://www.infopop.com/members/members.php
UBBCentral UBB.threads 6.2.3
-
UBBCentral UBB.Threads 6.5.2beta2
http://www.infopop.com/members/members.php
UBBCentral UBB.threads 6.5
-
UBBCentral UBB.Threads 6.5.2beta2
http://www.infopop.com/members/members.php
UBBCentral UBB.threads 6.5.1
-
UBBCentral UBB.Threads 6.5.2beta2
http://www.infopop.com/members/members.php
UBBCentral UBB.threads 6.5.1 .1
-
UBBCentral UBB.Threads 6.5.2beta2
http://www.infopop.com/members/members.php
References
UBBCentral UBB.Threads Multiple HTTP Response Splitting Vulnerabilities
References:
References:
- Infopop UBB Threads Multiple Vulnerabilities (Gulftech Research)
- UBB.Threads 6.5.2b2 Released to the Member Area (UBBCentral)
- UBB.threads Homepage (UBBCentral)