CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users and gain privileges via the line parameter in a docreate operation.
| Software | From | Fixed in |
|---|---|---|
| siteman / siteman | 1.1.9 | 1.1.9.x |
| siteman / siteman | 1.1.10 | 1.1.10.x |