PyroCMS HTTP Response Splitting and HTML Injection Vulnerabilities
19 Jun. 2012
Summary
PyroCMS is prone to multiple HTTP response-splitting vulnerabilities and multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, and influence or misrepresent how Web content is served, cached, or interpreted; other attacks are also possible.
Vendor Status:
Vendor had issued an update for this vulnerability.