Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-0202 (ExpressionEngine)

BugsAlert Home > CVE-2008-0202 (ExpressionEngine)
 
 

CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0202

Learn more about CVE-2008-0202 (ExpressionEngine)
 
Tags: cve-2008-0202 expressionengine

Related Items

      #401: links have target="undefined"

      CVE-2008-4369 (availscript_photo_album)

      session_name always default. Working in 5.2.6

      CVE-2008-5214 (clanlite)

      Novell GroupWise "SRC" Parameter Remote Stack Overflow Vulnerability

      Microsoft SQL Server 2000 "sp_replwritetovarbin()" Buffer Overflow

      DeeEmm CMS (DMCMS) 0.7.4 Multiple Remote Vulnerabilities

 

Pixel