First published: Tue Apr 19 2005(Updated: )
HTTP Response Splitting vulnerability in the Surveys module in PHP-Nuke 7.6 allows remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the forwarder parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Nuke | <=7.5 | |
PHP-Nuke | =7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1180 is considered a medium severity vulnerability due to its potential for web content spoofing and cache poisoning.
To fix CVE-2005-1180, upgrade PHP-Nuke to version 7.6 or apply any security patches released by the vendor.
CVE-2005-1180 can allow remote attackers to manipulate HTTP responses, potentially leading to spoofed content and compromised user interactions.
CVE-2005-1180 affects PHP-Nuke versions up to and including 7.6.
It is not safe to continue using PHP-Nuke if you are on a vulnerable version, as it exposes your site to potential security risks.