NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 54782 | CVE-2007-2618 | CRLF injection vulnerability in index.php in Drake CMS 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the lang parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS." | 2 | 5.1 | Medium | 2017-01-07 | 2012-10-30 | View | |
| 60419 | CVE-2006-1714 | CRLF injection vulnerability in index.php in Christoph Roeder phpMyForum 4.0 allows remote attackers to inject HTTP headers via hex-encoded CRLF sequences in the type parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 59996 | CVE-2006-1282 | CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequences in the Referrer HTTP header field, possibly when redirecting to other web pages. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 72585 | CVE-2004-2208 | CRLF injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to conduct HTTP response splitting attacks via unknown vectors. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 38855 | CVE-2013-2950 | CRLF injection vulnerability in IBM WebSphere Portal 6.1.0.x before 6.1.0.3 CF26, 6.1.5.x before 6.1.5 CF26, 7.0.0.x before 7.0.0.2 CF21, and 8.0.0.x through 8.0.0.1 CF5, when home substitution (aka uri.home.substitution) is enabled, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | 2 | 3.5 | Low | 2017-01-18 | 2013-06-04 | View |
Page 14962 of 17672, showing 5 records out of 88360 total, starting on record 74806, ending on 74810