CVE-2004-1584: CRLF Injection
Published Dec 31, 2004
·Updated
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.
Affected Software
1 affected component
WordPress=1.2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 20, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1584?
CVE-2004-1584 has a moderate severity rating as it allows for HTTP Response Splitting attacks.
2
How do I fix CVE-2004-1584?
To fix CVE-2004-1584, upgrade WordPress to version 1.2.1 or later.
3
Who is affected by CVE-2004-1584?
CVE-2004-1584 affects users running WordPress version 1.2.
4
What does CVE-2004-1584 allow attackers to do?
CVE-2004-1584 allows attackers to perform CRLF injection which can modify HTML content served to users.
5
Is CVE-2004-1584 specific to certain versions of WordPress?
Yes, CVE-2004-1584 specifically impacts WordPress version 1.2.