CVE-2005-2060
Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences…
Does this matter?
Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the Cat parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- ubbcentral/ubb.threads
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=111963737202040&w=2
- http://www.gulftech.org/?node=research&article_id=00084-06232005Patch, Vendor Advisory
- http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351Patch
- http://marc.info/?l=bugtraq&m=111963737202040&w=2
- http://www.gulftech.org/?node=research&article_id=00084-06232005Patch, Vendor Advisory
- http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.