MAXdev MD-Pro Multiple HTTP Response Splitting Vulnerabilities
BID:20754
Info
MAXdev MD-Pro Multiple HTTP Response Splitting Vulnerabilities
| Bugtraq ID: | 20754 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2006 12:00AM |
| Updated: | Oct 26 2006 10:13PM |
| Credit: | R00T[ATI] is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
MAXdev MD-Pro 1.0.76 |
| Not Vulnerable: | |
Discussion
MAXdev MD-Pro Multiple HTTP Response Splitting Vulnerabilities
MAXdev MD-Pro is prone to multiple HTTP response-splitting vulnerabilities because the application fails to properly sanitize user-supplied input.
A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.
MAXdev MD-Pro is prone to multiple HTTP response-splitting vulnerabilities because the application fails to properly sanitize user-supplied input.
A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.
Exploit / POC
MAXdev MD-Pro Multiple HTTP Response Splitting Vulnerabilities
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution / Fix
MAXdev MD-Pro Multiple HTTP Response Splitting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
MAXdev MD-Pro Multiple HTTP Response Splitting Vulnerabilities
References:
References:
- MAXdev MD-Pro Homepage (MAXdev)