Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the Cat parameter.
Threat-Mapped Scoring
Score: 0.0
Priority: Unclassified
EPSS
Score: 0.00335Percentile:
0.5575
CVSS Scoring
CVSS v2 Score: 5.0
Severity:
Affected Products
cpe:2.3:a:ubbcentral:ubb.threads:6.0:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.2:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.2.2:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.2.3:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.3:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.3.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.4:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.4.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.4.2:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.4.3:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.4.4:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.5:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.5.1.1:*:*:*:*:*:*:*
← Back to Home
BrownCoat Threat Intelligence Platform | 2025 Steve Gray — You Can’t Take the Sky from Me