CVE Vulnerabilities

CVE-2002-0490

Published: Aug 12, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Instant Web Mail before 0.60 does not properly filter CR/LF sequences, which allows remote attackers to (1) execute arbitrary POP commands via the id parameter in message.php, or (2) modify certain mail message headers via numerous parameters in write.php.

Affected Software

NameVendorStart VersionEnd Version
Instant_web_mailInstant_web_mail0.55 (including)0.55 (including)
Instant_web_mailInstant_web_mail0.56 (including)0.56 (including)
Instant_web_mailInstant_web_mail0.57 (including)0.57 (including)
Instant_web_mailInstant_web_mail0.58 (including)0.58 (including)
Instant_web_mailInstant_web_mail0.59 (including)0.59 (including)

References