CVE-2005-3348
Gravedad CVSS v2.0:
MEDIA
Tipo:
CWE-352
Falsificación de petición en sitios cruzados (Cross-Site Request Forgery)
Fecha de publicación:
18/11/2005
Última modificación:
03/04/2025
Descripción
*** Pendiente de traducción *** HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before 1.0.0.009, allows remote attackers to spoof web content and poison web caches via CRLF sequences in the charset parameter.
Impacto
Puntuación base 2.0
4.30
Gravedad 2.0
MEDIA
Productos y versiones vulnerables
CPE | Desde | Hasta |
---|---|---|
cpe:2.3:a:phpsysinfo:phpsysinfo:2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:phpsysinfo:phpsysinfo:2.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:phpsysinfo:phpsysinfo:2.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:phpsysinfo:phpsysinfo:2.4:*:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- http://secunia.com/advisories/17441
- http://secunia.com/advisories/17570
- http://secunia.com/advisories/17584
- http://secunia.com/advisories/17616
- http://secunia.com/advisories/17620
- http://secunia.com/advisories/17643
- http://secunia.com/advisories/17698
- http://www.debian.org/security/2005/dsa-897
- http://www.debian.org/security/2005/dsa-898
- http://www.debian.org/security/2005/dsa-899
- http://www.gentoo.org/security/en/glsa/glsa-200511-18.xml
- http://www.hardened-php.net/advisory_212005.81.html
- http://www.mandriva.com/security/advisories?name=MDKSA-2005%3A212
- http://www.securityfocus.com/archive/1/416543
- http://www.securityfocus.com/bid/15396
- http://www.securityfocus.com/bid/15414
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23107
- http://secunia.com/advisories/17441
- http://secunia.com/advisories/17570
- http://secunia.com/advisories/17584
- http://secunia.com/advisories/17616
- http://secunia.com/advisories/17620
- http://secunia.com/advisories/17643
- http://secunia.com/advisories/17698
- http://www.debian.org/security/2005/dsa-897
- http://www.debian.org/security/2005/dsa-898
- http://www.debian.org/security/2005/dsa-899
- http://www.gentoo.org/security/en/glsa/glsa-200511-18.xml
- http://www.hardened-php.net/advisory_212005.81.html
- http://www.mandriva.com/security/advisories?name=MDKSA-2005%3A212
- http://www.securityfocus.com/archive/1/416543
- http://www.securityfocus.com/bid/15396
- http://www.securityfocus.com/bid/15414
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23107