CVE-2007-4190
4.3
CVSS Score
Medium
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Link copied!
Description
CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in the url parameter. NOTE: this can be leveraged for cross-site scripting (XSS) attacks. NOTE: some of these details are obtained from third party information.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
M
Confidentiality
None
Integrity
P
Availability
None
Affected Software Configurations
- a joomla joomla\! * * * * * * * *
Weaknesses (CWE)
- CWE-74
References & External Links
- http://osvdb.org/38739
- http://secunia.com/advisories/26239
- http://www.joomla.org/content/view/3677/1/
- http://www.vupen.com/english/advisories/2007/2719
- http://osvdb.org/38739
- http://secunia.com/advisories/26239
- http://www.joomla.org/content/view/3677/1/
- http://www.vupen.com/english/advisories/2007/2719
External Resources
CVE History Timeline
Aug 08, 2007 14:33
Initial Analysis
Oct 01, 2021 15:03
Modified Analysis
May 14, 2024 01:47
CVE Modified
Nov 21, 2024 00:34
CVE Modified