Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the Cat parameter.
AV:N/AC:L/Au:N/C:N/I:P/A:N
This vulnerability has a 1.34% probability of being exploited in the next 30 days, ranking higher than 70% of all scored CVEs.