Cryptographp 'cryptographp.inc.php' HTTP Response Splitting Vulnerability
BID:53609
Info
Cryptographp 'cryptographp.inc.php' HTTP Response Splitting Vulnerability
| Bugtraq ID: | 53609 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2943 |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2012 12:00AM |
| Updated: | Mar 19 2015 07:35AM |
| Credit: | Lu33Y |
| Vulnerable: |
Cryptographp Cryptographp 0 |
| Not Vulnerable: | |
Discussion
Cryptographp 'cryptographp.inc.php' HTTP Response Splitting Vulnerability
Cryptographp is prone to an HTTP response-splitting vulnerability because it fails to sufficiently sanitize user-supplied data.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
Cryptographp is prone to an HTTP response-splitting vulnerability because it fails to sufficiently sanitize user-supplied data.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
Exploit / POC
Cryptographp 'cryptographp.inc.php' HTTP Response Splitting Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Cryptographp 'cryptographp.inc.php' HTTP Response Splitting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Cryptographp 'cryptographp.inc.php' HTTP Response Splitting Vulnerability
References:
References:
- Cryptographp Homepage (Cryptographp)