CVE-2005-1180: Medium severity Francisco Burzi PHP-Nuke vulnerability
HTTP Response Splitting vulnerability in the Surveys module in PHP-Nuke 7.6 allows remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the forwarder parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1180?
CVE-2005-1180 is considered a medium severity vulnerability due to its potential for web content spoofing and cache poisoning.
How do I fix CVE-2005-1180?
To fix CVE-2005-1180, upgrade PHP-Nuke to version 7.6 or apply any security patches released by the vendor.
What impact does CVE-2005-1180 have on my PHP-Nuke installation?
CVE-2005-1180 can allow remote attackers to manipulate HTTP responses, potentially leading to spoofed content and compromised user interactions.
Which versions of PHP-Nuke are affected by CVE-2005-1180?
CVE-2005-1180 affects PHP-Nuke versions up to and including 7.6.
Is it safe to continue using PHP-Nuke if I have CVE-2005-1180?
It is not safe to continue using PHP-Nuke if you are on a vulnerable version, as it exposes your site to potential security risks.