VulnerabilityModified
CVE-2005-1087
CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request.
MEDIUM 6.4EPSS 2.29%
Does this matter?
Lower severity and a low EPSS score (2.29%). Track it; it rarely justifies an emergency change on its own.
Description
CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- an/an-httpd
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/14861Vendor Advisory
- http://securitytracker.com/id?1013666Vendor Advisory
- http://www.osvdb.org/15362Vendor Advisory
- http://www.security.org.sg/vuln/anhttpd142n.htmlVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20031
- http://secunia.com/advisories/14861Vendor Advisory
- http://securitytracker.com/id?1013666Vendor Advisory
- http://www.osvdb.org/15362Vendor Advisory
- http://www.security.org.sg/vuln/anhttpd142n.htmlVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20031
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.