CVE-2005-0843 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 3.9% (pctl 90)
Patch early
A public exploit exists.
Description
CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter, which is included in the resulting Location header.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 3.9% — more likely to be exploited than 90% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-05-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| phorum | phorum |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Phorum 3.x/5.0.x - HTTP Response Splitting | 2005-03-22 |
References
→ the Explorer · watch your stack · NVD