CVE-2007-2618
Last modified
CVE-2007-2618 is a vulnerability of currently unknown severity. CRLF injection vulnerability in index.php in Drake CMS 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the lang parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS.". EPSS estimates a 1.19% chance of exploitation in the next 30 days.
Description
CRLF injection vulnerability in index.php in Drake CMS 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the lang parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Drake Team | Drake Cms | 0.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2618?
How severe is CVE-2007-2618?
How do I fix CVE-2007-2618?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-2612SQL injection vulnerability in libs/Wakka.class.php in Wikka…
- CVE-2007-2613WikkaWiki (Wikka Wiki) before 1.1.6.3 allows attackers in a …
- CVE-2007-2614PHP remote file inclusion vulnerability in examples/widget8.…
- CVE-2007-2615Multiple PHP remote file inclusion vulnerabilities in Crie s…
- CVE-2007-2616Stack-based buffer overflow in the SSL version of the NMDMC.…
- CVE-2007-2617srsexec in Sun Remote Services (SRS) Net Connect Software Pr…
- CVE-2007-2619Symantec pcAnywhere 11.5.x and 12.0.x retains unencrypted lo…
- CVE-2007-2620PHP remote file inclusion vulnerability in inc/config.inc.ph…
- CVE-2007-2621SQL injection vulnerability in event_view.php in Thyme Calen…
- CVE-2007-2622Multiple SQL injection vulnerabilities in TaskDriver 1.2 and…
- CVE-2007-2623Multiple buffer overflows in RControl.dll in Remote Display …
- CVE-2007-2624Dynamic variable evaluation vulnerability in shared/config/c…
Are you affected by CVE-2007-2618?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
