Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-40324 — Proof-of-concept for CRLF injection in E-Staff v5.1, demonstrating HTTP response splitting and header manipulation for security testing. | Kitploit
Tools/GitHubGitHub/aleksey-vi/cve-2024-40324
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubaleksey-vi/cve-2024-40324

CVE-2024-40324

Proof-of-concept for CRLF injection in E-Staff v5.1, demonstrating HTTP response splitting and header manipulation for security testing.

View Repository
12 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-40324

Description

A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.

Vulnerability Type

CRLF

Vendor of Product

E-Staff

Affected Product Code Base

E-Staff 5.1

Affected Component

HTTP headers

Attack Type

Remote

Impact Code execution

Potential for arbitrary header injection, cache poisoning, and session hijacking, cross-site scripting (XSS), and other exploits.

Discoverer

  • Aleksey Vistorobskiy

Attack Vectors

An attacker can insert CRLF characters into input fields, manipulating HTTP headers. For example, injecting CRLF into HTTP headers can result in HTTP response splitting

Screenshot:

Reference

  • https://e-staff.ru/estaff_home
  • https://github.com/aleksey-vi/CVE-2024-40324
Download Tool