Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF (%0d%0a) sequences in the (1) products_id or (2) pid parameter to index.php or (3) goto parameter to banner.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Oscommerce | Oscommerce | 2.1 (including) | 2.1 (including) |
Oscommerce | Oscommerce | 2.2_cvs (including) | 2.2_cvs (including) |
Oscommerce | Oscommerce | 2.2_ms1 (including) | 2.2_ms1 (including) |
Oscommerce | Oscommerce | 2.2_ms2 (including) | 2.2_ms2 (including) |