PT-2005-3719 · Thesitewizard.Com · Chfeedback.Pl Feedback Form Perl Script
Publicado
2005-09-08
·
Atualizado
2008-09-05
·
CVE-2005-2854
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
thesitewizard.com chfeedback.pl Feedback Form Perl Script version 2.0.1
Description
A CRLF injection issue exists, allowing remote attackers to use the script as a mail relay via CRLF sequences in the
name or email fields, which are injected into mail headers.Recommendations
For thesitewizard.com chfeedback.pl Feedback Form Perl Script version 2.0.1, consider validating and sanitizing user input in the
name and email fields to prevent CRLF injection. As a temporary workaround, restrict access to the script until a patch is available.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Chfeedback.Pl Feedback Form Perl Script