WebCalendar Layers_Toggle.PHP HTTP Response Splitting Vulnerability
BID:15673
Info
WebCalendar Layers_Toggle.PHP HTTP Response Splitting Vulnerability
| Bugtraq ID: | 15673 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3982 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2005 12:00AM |
| Updated: | Dec 15 2006 09:03PM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
k5n WebCalendar 1.0.1 k5n WebCalendar 0.1 .0 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
WebCalendar Layers_Toggle.PHP HTTP Response Splitting Vulnerability
WebCalendar is prone to an HTTP response-splitting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.
WebCalendar 1.0.1 is vulnerable; other versions may also be affected.
WebCalendar is prone to an HTTP response-splitting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.
WebCalendar 1.0.1 is vulnerable; other versions may also be affected.
Exploit / POC
WebCalendar Layers_Toggle.PHP HTTP Response Splitting Vulnerability
An exploit is not required.
An example URI has been provided:
http://www.example.com/webcalendar/layers_toggle.php?status=on&ret=[url_redirect_to]
An exploit is not required.
An example URI has been provided:
http://www.example.com/webcalendar/layers_toggle.php?status=on&ret=[url_redirect_to]
Solution / Fix
WebCalendar Layers_Toggle.PHP HTTP Response Splitting Vulnerability
Solution:
Please see the references for vendor advisories and more information.
Solution:
Please see the references for vendor advisories and more information.
References
WebCalendar Layers_Toggle.PHP HTTP Response Splitting Vulnerability
References:
References: