peter bassill · operator
$ cve CVE-2005-0843 JSON

CVE-2005-0843 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 3.9% (pctl 90)

Patch early

A public exploit exists.

Description

CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter, which is included in the resulting Location header.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS3.9% — more likely to be exploited than 90% of all CVEs
On CISA KEVno
Public exploityes
Published2005-05-02
Last modified2026-06-16

Affected (1)

VendorProduct
phorumphorum

Public exploits

SourceTitleDate
exploit-dbPhorum 3.x/5.0.x - HTTP Response Splitting2005-03-22

References

→ the Explorer  ·  watch your stack  ·  NVD