CVE-2011-4545: Code Injection
Published Dec 2, 2011
·Updated
CRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the name parameter.
Affected Software
1 affected component
Prestashop PrestaShop=1.4.4.1
Event History
Dec 2, 2011
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4545?
The severity of CVE-2011-4545 is classified as high due to its potential for remote exploitation.
2
How do I fix CVE-2011-4545?
To fix CVE-2011-4545, upgrade to a patched version of Prestashop that addresses this vulnerability.
3
What are the potential impacts of CVE-2011-4545?
The potential impacts of CVE-2011-4545 include arbitrary HTTP header injection and HTTP response splitting attacks.
4
Which versions of Prestashop are affected by CVE-2011-4545?
Prestashop version 1.4.4.1 is the affected version referenced in CVE-2011-4545.
5
Can CVE-2011-4545 be exploited remotely?
Yes, CVE-2011-4545 can be exploited remotely by attackers through crafted HTTP requests.