5

CVE-2006-0631

Exploit
CRLF injection vulnerability in mailback.pl in Erik C. Thauvin mailback allows remote attackers to use mailback as a "spam proxy" by modifying mail headers, including recipient e-mail addresses, via newline characters in the Subject field.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.62% 0.729
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://seclists.org/lists/bugtraq/2006/Feb/0094.html
http://seclists.org/lists/bugtraq/2006/Feb/0154.html
Exploit
http://secunia.com/advisories/18748
Patch
Vendor Advisory
http://vc.thauvin.net/cvs/cgi/mailback/mailback.pl?view=log
http://www.osvdb.org/22955
Patch
http://www.vupen.com/english/advisories/2006/0459
https://exchange.xforce.ibmcloud.com/vulnerabilities/24540