CVE-2007-2046
Last modified
CVE-2007-2046 is a vulnerability of currently unknown severity. Multiple CRLF injection vulnerabilities in adclick.php in (a) Openads (phpAdsNew) 2.0.11 and earlier and (b) Openads for PostgreSQL (phpPgAds) 2.0.11 and earlier allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in (1) the dest parameter and (2) the Referer HTTP header. NOTE: some of these details are obtained from third party information.. EPSS estimates a 1.40% chance of exploitation in the next 30 days.
Description
Multiple CRLF injection vulnerabilities in adclick.php in (a) Openads (phpAdsNew) 2.0.11 and earlier and (b) Openads for PostgreSQL (phpPgAds) 2.0.11 and earlier allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in (1) the dest parameter and (2) the Referer HTTP header. NOTE: some of these details are obtained from third party information.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openads | Openads | <= 2.0.11 |
References
- http://secunia.com/advisories/24876Patch, Vendor Advisory
- http://secunia.com/advisories/24876Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2046?
How severe is CVE-2007-2046?
How do I fix CVE-2007-2046?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-2040Cisco Aironet 1000 Series and 1500 Series Lightweight Access…
- CVE-2007-2041Cisco Wireless LAN Controller (WLC) before 4.0.206.0 saves t…
- CVE-2007-2042Multiple PHP remote file inclusion vulnerabilities in the Av…
- CVE-2007-2043Multiple PHP remote file inclusion vulnerabilities in the Av…
- CVE-2007-2044PHP remote file inclusion vulnerability in mod_weather.php i…
- CVE-2007-2045Unspecified vulnerability in the IP implementation in Sun So…
- CVE-2007-2047CRLF injection vulnerability in www/delivery/ck.php in Opena…
- CVE-2007-2048Directory traversal vulnerability in /console in the Managem…
- CVE-2007-2049Multiple PHP remote file inclusion vulnerabilities in the Ca…
- CVE-2007-2050Multiple directory traversal vulnerabilities in header.php i…
- CVE-2007-2051Buffer overflow in the parsecmd function in bftpd before 1.8…
- CVE-2007-2052Off-by-one error in the PyLocale_strxfrm function in Modules…
Are you affected by CVE-2007-2046?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
