CVE-2013-2652

CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the item parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
VendorProductVersion
andrew_simpsonwebcollab
𝑥
≤ 3.30
andrew_simpsonwebcollab
1.3:beta
andrew_simpsonwebcollab
1.30
andrew_simpsonwebcollab
1.31
andrew_simpsonwebcollab
1.32
andrew_simpsonwebcollab
1.40
andrew_simpsonwebcollab
1.41
andrew_simpsonwebcollab
1.42
andrew_simpsonwebcollab
1.50
andrew_simpsonwebcollab
1.51
andrew_simpsonwebcollab
1.60
andrew_simpsonwebcollab
1.60a:a
andrew_simpsonwebcollab
1.61
andrew_simpsonwebcollab
1.62
andrew_simpsonwebcollab
1.62a:a
andrew_simpsonwebcollab
1.70
andrew_simpsonwebcollab
1.71
andrew_simpsonwebcollab
1.71a:a
andrew_simpsonwebcollab
1.80
andrew_simpsonwebcollab
1.81
andrew_simpsonwebcollab
2.00
andrew_simpsonwebcollab
2.01
andrew_simpsonwebcollab
2.10
andrew_simpsonwebcollab
2.11
andrew_simpsonwebcollab
2.20
andrew_simpsonwebcollab
2.30
andrew_simpsonwebcollab
2.31
andrew_simpsonwebcollab
2.40
andrew_simpsonwebcollab
2.50
andrew_simpsonwebcollab
2.60
andrew_simpsonwebcollab
2.61
andrew_simpsonwebcollab
2.70
andrew_simpsonwebcollab
2.71
andrew_simpsonwebcollab
3.00
andrew_simpsonwebcollab
3.10
andrew_simpsonwebcollab
3.20
andrew_simpsonwebcollab
3.21
𝑥
= Vulnerable software versions