Joined: 13 Jun 2003
Location: Dresden, Germany
|Posted: Sat Nov 27, 2004 1:15 am Post subject: [ GLSA 200411-35 ] phpWebSite: HTTP response splitting vulne
|Gentoo Linux Security Advisory
Title: phpWebSite: HTTP response splitting vulnerability (GLSA 200411-35)
Date: November 26, 2004
Updated: May 22, 2006
phpWebSite is vulnerable to possible HTTP response splitting attacks.
phpWebSite is a web site content management system.
Vulnerable: < 0.9.3_p4-r2
Unaffected: >= 0.9.3_p4-r2
Architectures: All supported architectures
Due to lack of proper input validation, phpWebSite has been found to be vulnerable to HTTP response splitting attacks.
A malicious user could inject arbitrary response data, leading to content spoofing, web cache poisoning and other cross-site scripting or HTTP response splitting attacks. This could result in compromising the victim's data or browser.
There is no known workaround at this time.
All phpWebSite users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/phpwebsite-0.9.3_p4-r2"
Last edited by GLSA on Tue May 23, 2006 4:18 am; edited 2 times in total