Member Login Script 3.3 Client-Side Request Desynchronization Vulnerability
Vulnerability Description
Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP request handling by exploiting Content-Length header parsing. Attackers can send crafted POST requests with smuggled secondary requests to potentially bypass server-side request processing controls.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53878
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- nu11secur1ty
References
Affected Vendor
Phpjabbers
View all reports →