Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, BCC, and other header fields in the generated email message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MIT CGIEmail任意邮件接收中继漏洞
Vulnerability Description
cgiemail存在漏洞。远程攻击者可以借助回车换行向例如 "required-subject,"的参数中注入换行符(%0a)的编码字符。该漏洞可以用来修改抄送,密送以及其他邮件消息中的头字段。
CVSS Information
N/A
Vulnerability Type
N/A