← Back

CVE-2013-1647

nvd nist
Published: Sep 5, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter, as demonstrated by (1) the location parameter to ajax/redirect or (2) multiple infostore URIs.

Affected (3)

1 product
Open Xchange Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Open Xchange
Version 6.20.7
Version 6.22.0
Version 6.22.1

References (2)

Timeline

No history available yet.