F*EX '/rup' HTTP Response Splitting Vulnerability
BID:67783
CVE-2014-3875 |Info
F*EX '/rup' HTTP Response Splitting Vulnerability
| Bugtraq ID: | 67783 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3875 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2014 12:00AM |
| Updated: | Jun 03 2014 12:00AM |
| Credit: | LSE Leading Security Experts GmbH |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
F*EX '/rup' HTTP Response Splitting Vulnerability
F*EX is prone to an HTTP response-splitting vulnerability because it fails to sufficiently sanitize user-supplied data.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
Versions prior to F*EX 20140530 are vulnerable.
F*EX is prone to an HTTP response-splitting vulnerability because it fails to sufficiently sanitize user-supplied data.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
Versions prior to F*EX 20140530 are vulnerable.
Exploit / POC
F*EX '/rup' HTTP Response Splitting Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
F*EX '/rup' HTTP Response Splitting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
F*EX '/rup' HTTP Response Splitting Vulnerability
References:
References:
- F*EX Homepage (F*EX)
- Release Notes (F*EX)