Exploit
CVE-2018-16979

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') (CWE-113)

Published: Sep 12, 2018 / Updated: 73mo ago

010
No CVSS yetEPSS 0.12%
CVE info copied to clipboard

Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-2943.

Timeline

First Article

Feedly found the first article mentioning CVE-2018-16979. See article

Sep 12, 2018 at 11:52 PM / cve.mitre.org
EPSS

EPSS Score was set to: 0.12% (Percentile: 45.5%)

Oct 17, 2023 at 11:45 PM
Static CVE Timeline Graph

Affected Systems

Monstra/monstra
+null more

Exploits

https://github.com/howchen/howchen/issues/4
+null more

Attack Patterns

CAPEC-31: Accessing/Intercepting/Modifying HTTP Cookies
+null more

Be the first to know about critical vulnerabilities

Collect, analyze, and share vulnerability reports faster using AI