CVE Vulnerabilities

CVE-2002-0490

Published: Aug 12, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Instant Web Mail before 0.60 does not properly filter CR/LF sequences, which allows remote attackers to (1) execute arbitrary POP commands via the id parameter in message.php, or (2) modify certain mail message headers via numerous parameters in write.php.

Affected Software

Name Vendor Start Version End Version
Instant_web_mail Instant_web_mail 0.55 (including) 0.55 (including)
Instant_web_mail Instant_web_mail 0.56 (including) 0.56 (including)
Instant_web_mail Instant_web_mail 0.57 (including) 0.57 (including)
Instant_web_mail Instant_web_mail 0.58 (including) 0.58 (including)
Instant_web_mail Instant_web_mail 0.59 (including) 0.59 (including)

References