CVE Vulnerabilities

CVE-2002-1575

Published: Mar 03, 2004 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as required-subject, which can be used to modify the CC, BCC, and other header fields in the generated email message.

Affected Software

Name Vendor Start Version End Version
Cgiemail Mit 1.6 (including) 1.6 (including)

References