CVE-2004-1656 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 2.28% — more likely to be exploited than 83% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-09-01 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| comersus open technologies | comersus cart |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Comersus Cart 5.0 - HTTP Response Splitting | 2004-09-01 |
References
→ the Explorer · watch your stack · NVD