CVE-2004-1620: CRLF Injection
Published Oct 21, 2004
·Updated
CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer field in comment.php.
Affected Software
14 affected components
S9Y serendipity=0.5
S9Y serendipity=0.4
S9Y serendipity=0.7_beta1
S9Y serendipity=0.6_rc1
S9Y serendipity=0.5_pl1
S9Y serendipity=0.6_pl2
S9Y serendipity=0.7_beta3
S9Y serendipity=0.7_beta4
S9Y serendipity=0.6_pl1
S9Y serendipity=0.3
S9Y serendipity=0.6_pl3
S9Y serendipity=0.6_rc2
S9Y serendipity=0.7_beta2
S9Y serendipity=0.6
Remediation
Patch Available
Patch Available
Patch Available
Event History
Oct 21, 2004
CVE Published
04:00 AM
Feb 20, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1620?
The severity of CVE-2004-1620 is considered to be moderate due to its ability to facilitate HTTP Response Splitting attacks.
2
How do I fix CVE-2004-1620?
To fix CVE-2004-1620, you should upgrade to Serendipity version 0.7rc1 or later.
3
Which versions of Serendipity are affected by CVE-2004-1620?
CVE-2004-1620 affects all Serendipity versions prior to 0.7rc1.
4
What kind of attack can be executed using CVE-2004-1620?
CVE-2004-1620 can be exploited to perform HTTP Response Splitting attacks.
5
Where in Serendipity is CVE-2004-1620 found?
CVE-2004-1620 is found in the url parameter of index.php, exit.php, and the HTTP Referer field in comment.php.