CVE-2007-0892
CRLF injection vulnerability in phpMyVisites before 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the url parameter, when the pagename parameter begins with "FILE:".
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
CRLF injection vulnerability in phpMyVisites before 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the url parameter, when the pagename parameter begins with "FILE:".
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.47% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-93
- Affected
- matthieu aubry/phpmyvisites
- Source
- cve@mitre.org
References
- http://marc.info/?l=full-disclosure&m=117121596803908&w=2Third Party Advisory
- http://osvdb.org/33177Broken Link
- http://www.securityfocus.com/archive/1/459792/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32428
- http://marc.info/?l=full-disclosure&m=117121596803908&w=2Third Party Advisory
- http://osvdb.org/33177Broken Link
- http://www.securityfocus.com/archive/1/459792/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32428
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.