Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the redirect parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FormMail HTTP响应拆分和跨站脚本漏洞
Vulnerability Description
FormMail是一款跨平台用Perl实现的基于Web的邮件网关产品。 FormMail.pl模块没有正确地验证用户所提交的request和return_link_url参数,远程攻击者可以通过提交恶意请求执行跨站脚本攻击,或在返回给用户的响应中包含任意HTTP头。
CVSS Information
N/A
Vulnerability Type
N/A