CVE-2004-1516: CRLF Injection
CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the blockusername parameter in the user module.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1516?
The severity of CVE-2004-1516 is considered moderate due to its potential for HTTP Response Splitting attacks.
How do I fix CVE-2004-1516?
To fix CVE-2004-1516, update phpWebSite to version 0.9.3.5 or later, which addresses the CRLF injection vulnerability.
Which versions are affected by CVE-2004-1516?
CVE-2004-1516 affects phpWebSite versions 0.7.3 up to 0.9.3.4.
What kind of attack can be executed due to CVE-2004-1516?
CVE-2004-1516 can be exploited to perform HTTP Response Splitting attacks, allowing attackers to modify the server's HTML content.
Who discovered CVE-2004-1516?
CVE-2004-1516 was publicly acknowledged and reported through various security channels, including announcements on phpWebSite and vulnerability databases.