vendor:
SnipSnap
by:
Unknown
5.5
CVSS
MEDIUM
HTTP response splitting
113
CWE
Product Name: SnipSnap
Affected Version From: 0.5.2a and prior
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:snipsnap_project:snipsnap:0.5.2a
Platforms Tested:
Unknown
SnipSnap HTTP Response Splitting Vulnerability
The 'referer' parameter in SnipSnap is prone to an HTTP response splitting vulnerability. This allows an attacker to manipulate how POST requests are handled.
Mitigation:
Upgrade to a version of SnipSnap that has addressed this vulnerability.