Link Log – external link click monitor <= 1.4 - HTTP Response Splitting

2015-04-28 00:00
Anonymous

Strategic Overview

Status
Patched in 2.0
Affected Version<= 1.4
CVSS7.5High
CVECVE-2015-9345
View all Smart External Link Click Monitor [Link Log] vulnerabilities

Vulnerability Overview

The Link Log plugin for WordPress is vulnerable to HTTP Response Splitting in versions up to, and including 1.4. This is due to improper input validation. This makes it possible for unauthenticated attackers to perform various other future attacks such as XSS, Cross-User Defacement, Web Cache Poisoning, etc.

Technical Analysis

REMEDIATION: Update to version 2.0, or a newer patched version --- IDENTIFIER: CWE-113 (Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')) The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C