Lucene search

K
cveMitreCVE-2004-1687
HistoryFeb 20, 2005 - 5:00 a.m.

CVE-2004-1687

2005-02-2005:00:00
mitre
web.nvd.nist.gov
23
crlf injection
snitz forums 2000
http response splitting
cve-2004-1687
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.8

Confidence

Low

EPSS

0.014

Percentile

86.7%

CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter.

Affected configurations

Nvd
Node
snitz_communicationssnitz_forums_2000Match3.0
OR
snitz_communicationssnitz_forums_2000Match3.1sr4
OR
snitz_communicationssnitz_forums_2000Match3.3
OR
snitz_communicationssnitz_forums_2000Match3.3.01
OR
snitz_communicationssnitz_forums_2000Match3.3.02
OR
snitz_communicationssnitz_forums_2000Match3.3.03
OR
snitz_communicationssnitz_forums_2000Match3.4.02
OR
snitz_communicationssnitz_forums_2000Match3.4.03
OR
snitz_communicationssnitz_forums_2000Match3.4.04
VendorProductVersionCPE
snitz_communicationssnitz_forums_20003.0cpe:2.3:a:snitz_communications:snitz_forums_2000:3.0:*:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.1cpe:2.3:a:snitz_communications:snitz_forums_2000:3.1:sr4:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.3cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3:*:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.3.01cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.01:*:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.3.02cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.02:*:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.3.03cpe:2.3:a:snitz_communications:snitz_forums_2000:3.3.03:*:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.4.02cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.02:*:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.4.03cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.03:*:*:*:*:*:*:*
snitz_communicationssnitz_forums_20003.4.04cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.04:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.8

Confidence

Low

EPSS

0.014

Percentile

86.7%

Related for CVE-2004-1687