Back

CVE-2004-1620

CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer field in comment.php.

Published: Oct 21, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (14)

Vendor Product Version
s9y serendipity 0.3
s9y serendipity 0.4
s9y serendipity 0.5
s9y serendipity 0.5_pl1
s9y serendipity 0.6
s9y serendipity 0.6_pl1
s9y serendipity 0.6_pl2
s9y serendipity 0.6_pl3
s9y serendipity 0.6_rc1
s9y serendipity 0.6_rc2
s9y serendipity 0.7_beta1
s9y serendipity 0.7_beta2
s9y serendipity 0.7_beta3
s9y serendipity 0.7_beta4

GitHub Security Advisory GHSA-3hfj-vjmw-rjj4

CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 8.14%

Top 6% most likely to be exploited

Threat Score 22.4 / 100

Data Sources

NVD EPSS GitHub