CVE-2006-6965
published 2007-01-29CVE-2006-6965: CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.32%
67.7th percentile
CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the media parameter. NOTE: this issue can be leveraged for XSS attacks.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| debian | dokuwiki | < dokuwiki 0.0.20061106-1 (bookworm) | dokuwiki 0.0.20061106-1 (bookworm) |
| dokuwiki | dokuwiki | >= 0 < 0.0.20061106-1 | 0.0.20061106-1 |
| dokuwiki | dokuwiki | >= 0 < 0.0.20061106-1 | 0.0.20061106-1 |
| dokuwiki | dokuwiki | >= 0 < 0.0.20061106-1 | 0.0.20061106-1 |
| dokuwiki | dokuwiki | >= 0 < 0.0.20061106-1 | 0.0.20061106-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2006-6965: dokuwiki - CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and p...
vendor_debian·2006·CVSS 4.3
CVE-2006-6965 [MEDIUM] CVE-2006-6965: dokuwiki - CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and p...
CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the media parameter. NOTE: this issue can be leveraged for XSS attacks.
Scope: local
bookworm: resolved (fixed in 0.0.20061106-1)
bullseye: resolved (fixed in 0.0.20061106-1)
forky: resolved (fixed in 0.0.20061106-1)
sid: resolved (fixed in 0.0.20061106-1)
trixie: resolved (fixed in 0.0.20061106-1)
GHSA
GHSA-653g-8hw7-x2fj: CRLF injection vulnerability in lib/exe/fetch
ghsa_unreviewed·2022-05-01
CVE-2006-6965 [MEDIUM] GHSA-653g-8hw7-x2fj: CRLF injection vulnerability in lib/exe/fetch
CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the media parameter. NOTE: this issue can be leveraged for XSS attacks.
OSV
CVE-2006-6965: CRLF injection vulnerability in lib/exe/fetch
osv·2007-01-29·CVSS 4.3
CVE-2006-6965 [MEDIUM] CVE-2006-6965: CRLF injection vulnerability in lib/exe/fetch
CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the media parameter. NOTE: this issue can be leveraged for XSS attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/31620http://secunia.com/advisories/23926http://secunia.com/advisories/24853http://security.gentoo.org/glsa/glsa-200704-08.xmlhttp://sla.ckers.org/forum/read.php?3%2C880%2C1361#msg-1361http://www.securityfocus.com/bid/22236http://www.vupen.com/english/advisories/2007/0357https://exchange.xforce.ibmcloud.com/vulnerabilities/31930http://osvdb.org/31620http://secunia.com/advisories/23926http://secunia.com/advisories/24853http://security.gentoo.org/glsa/glsa-200704-08.xmlhttp://sla.ckers.org/forum/read.php?3%2C880%2C1361#msg-1361http://www.securityfocus.com/bid/22236http://www.vupen.com/english/advisories/2007/0357https://exchange.xforce.ibmcloud.com/vulnerabilities/31930
2007-01-29
Published