OSVDB ID: 11013

Title: Serendipity index.php Requested URL HTTP Response Splitting

Info

Disclosure

Oct 21, 2004

Discovery

Unknown

Dates

Exploit

Oct 22, 2004

Solution

Unknown

Description

Serendipity contains a flaw that may allow a malicious user to perform HTTP response splitting on the index.php page. The issue is triggered when unexpected carriage return and/or line feed (CR/LF) characters are input into the HTTP request stream. It is possible that the flaw may allow man-in-the-middle attacks and or cross-site-scripting attacks, resulting in a loss of confidentiality and/or integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Public
Disclosure: OSVDB Verified, Vendor Verified
OSVDB: Web Related

Solution

Upgrade to version 0.7-rc1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

S9Y

Serendipity

0.7betax

References

Credit

  • Chaotic Evil - chaoticevilspyring.com -


Direct URL: http://osvdb.org/11013