CVE-2013-1647: Code Injection
Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter, as demonstrated by (1) the location parameter to ajax/redirect or (2) multiple infostore URIs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1647?
CVE-2013-1647 has been rated as Medium severity due to the potential for unauthorized HTTP header injection and HTTP response splitting attacks.
Which versions of Open-Xchange are affected by CVE-2013-1647?
CVE-2013-1647 affects Open-Xchange Server versions prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14.
How do I fix CVE-2013-1647?
To fix CVE-2013-1647, you should upgrade Open-Xchange Server to the latest version that includes the security patches addressing the vulnerability.
What types of attacks can be conducted using CVE-2013-1647?
CVE-2013-1647 allows remote attackers to conduct HTTP response splitting attacks by injecting arbitrary HTTP headers.
Is there any workaround for CVE-2013-1647?
There are no specific workarounds for CVE-2013-1647, so applying the appropriate security updates is strongly recommended.