CVE-2007-2046: CRLF Injection

Published Apr 16, 2007
·
Updated

Multiple CRLF injection vulnerabilities in adclick.php in (a) Openads (phpAdsNew) 2.0.11 and earlier and (b) Openads for PostgreSQL (phpPgAds) 2.0.11 and earlier allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in (1) the dest parameter and (2) the Referer HTTP header. NOTE: some of these details are obtained from third party information.

Affected Software

2 affected components
Openads Openads<=2.0.11
Openads Openads<=2.0.11

Event History

Apr 16, 2007
CVE Published
10:19 PM
Apr 17, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2007-2046?

CVE-2007-2046 is considered a medium severity vulnerability due to its potential for causing HTTP response splitting attacks.

2

How do I fix CVE-2007-2046?

To fix CVE-2007-2046, upgrade to Openads version 2.0.12 or higher, which addresses these CRLF injection vulnerabilities.

3

What software is affected by CVE-2007-2046?

CVE-2007-2046 affects Openads (phpAdsNew) 2.0.11 and earlier, as well as Openads for PostgreSQL (phpPgAds) 2.0.11 and earlier.

4

What are the consequences of exploiting CVE-2007-2046?

Exploiting CVE-2007-2046 can allow remote attackers to inject arbitrary HTTP headers, leading to security issues such as session hijacking or defacement.

5

How can I detect CVE-2007-2046 in my application?

You can detect CVE-2007-2046 by reviewing your server logs for unusual HTTP header patterns and verifying the version of Openads in use.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203