peter bassill · operator
$ cve CVE-2005-1087 JSON

CVE-2005-1087 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 2.3% (pctl 83)

Patch early

A public exploit exists.

Description

CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS2.29% — more likely to be exploited than 83% of all CVEs
On CISA KEVno
Public exploityes
Published2005-04-07
Last modified2026-06-16

Affected (1)

VendorProduct
anan-httpd

Public exploits

SourceTitleDate
exploit-dbAN HTTPD 1.42 - Arbitrary Log Content Injection2005-04-08

References

→ the Explorer  ·  watch your stack  ·  NVD