Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d character. (Also, the message parameter can have initial HTML comment characters.)
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
eGain Web Email 输入验证错误漏洞
Vulnerability Description
eGain Web Email 11之前版本中存在输入验证错误漏洞。远程攻击者可借助特制请求利用该漏洞注入任意HTTP标头。
CVSS Information
N/A
Vulnerability Type
N/A