Total vulnerabilities in the database
CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the PHPSESSID parameter.
Software | From | Fixed in |
---|---|---|
codeworx_technologies / dcp-portal | 3.7 | 3.7.x |
codeworx_technologies / dcp-portal | 5.0.2 | 5.0.2.x |
codeworx_technologies / dcp-portal | 5.2 | 5.2.x |
codeworx_technologies / dcp-portal | 4.1 | 4.1.x |
codeworx_technologies / dcp-portal | 5.3 | 5.3.x |
codeworx_technologies / dcp-portal | 5.0.1 | 5.0.1.x |
codeworx_technologies / dcp-portal | - | 5.3.2.x |
codeworx_technologies / dcp-portal | 5.3.1 | 5.3.1.x |
codeworx_technologies / dcp-portal | 4.5.1 | 4.5.1.x |
codeworx_technologies / dcp-portal | 4.2 | 4.2.x |
codeworx_technologies / dcp-portal | 4.0 | 4.0.x |
codeworx_technologies / dcp-portal | 5.1 | 5.1.x |