CVE Vulnerabilities

CVE-2006-7020

Published: Feb 15, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:C/A:N
RedHat/V2
RedHat/V3
Ubuntu

CRLF injection vulnerability in (1) include/inc_act/act_formmailer.php and possibly (2) sample_ext_php/mail_file_form.php in phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to modify HTTP headers and send spam e-mail via a spoofed HTTP Referer (HTTP_REFERER).

Affected Software

Name Vendor Start Version End Version
Phpwcms Oliver_georgi * 1.1_rc3 (including)
Phpwcms Oliver_georgi * 1.2.5_dev (including)

References