CVE-2005-0843: CRLF Injection
Published Mar 24, 2005
·Updated
CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter, which is included in the resulting Location header.
Affected Software
1 affected component
Phorum Phorum=5.0.14a
Remediation
Patch Available
Event History
Mar 24, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0843?
CVE-2005-0843 is considered a moderate severity vulnerability due to the potential for HTTP Response Splitting attacks.
2
How do I fix CVE-2005-0843?
To fix CVE-2005-0843, upgrade Phorum to a version that has patched this CRLF injection vulnerability.
3
What are the implications of exploiting CVE-2005-0843?
Exploiting CVE-2005-0843 could allow attackers to manipulate HTTP responses and redirect users without their consent.
4
Which software versions are affected by CVE-2005-0843?
CVE-2005-0843 specifically affects Phorum version 5.0.14a.
5
Can CVE-2005-0843 be exploited remotely?
Yes, CVE-2005-0843 can be exploited remotely by attackers using crafted input to the search.php page.