First published: Fri Dec 31 2004(Updated: )
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | =1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1584 has a moderate severity rating as it allows for HTTP Response Splitting attacks.
To fix CVE-2004-1584, upgrade WordPress to version 1.2.1 or later.
CVE-2004-1584 affects users running WordPress version 1.2.
CVE-2004-1584 allows attackers to perform CRLF injection which can modify HTML content served to users.
Yes, CVE-2004-1584 specifically impacts WordPress version 1.2.