CVE-2004-1516 describes a CRLF injection vulnerability in phpWebSite 0.9.3-4, specifically within the index.php file's user module. This flaw allows remote attackers to perform HTTP Response Splitting attacks by manipulating the block_username parameter, potentially modifying the expected HTML content returned to users. The vulnerability has a CVSS score of 5.0, indicating a medium severity, with no authentication required and only partial impact on integrity. There is no evidence of active exploitation, nor are there public exploits available in Metasploit or ExploitDB, though it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.7.3CPE matchmatch criteria | cpe:2.3:a:phpwebsite:phpwebsite:0.7.3:*:*:*:*:*:*:* | ||
0.8.2CPE matchmatch criteria | cpe:2.3:a:phpwebsite:phpwebsite:0.8.2:*:*:*:*:*:*:* | ||
0.8.3CPE matchmatch criteria | cpe:2.3:a:phpwebsite:phpwebsite:0.8.3:*:*:*:*:*:*:* | ||
0.9.3CPE matchmatch criteria | cpe:2.3:a:phpwebsite:phpwebsite:0.9.3:*:*:*:*:*:*:* | ||
0.9.3.1CPE matchmatch criteria | cpe:2.3:a:phpwebsite:phpwebsite:0.9.3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.