Multiple CRLF injection vulnerabilities in Devellion CubeCart 3.0.15 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a cookie name beginning with "ccSID" to (1) cart.php or (2) index.php.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2007-05-09T10:00:00
Updated: 2024-08-07T13:42:33.425Z
Reserved: 2007-05-08T00:00:00
Link: CVE-2007-2550
Vulnrichment
No data.
NVD
Status : Modified
Published: 2007-05-09T10:19:00.000
Modified: 2024-11-21T00:31:03.473
Link: CVE-2007-2550
Redhat
No data.