PT-2006-1765 · Squishdot · Squishdot

Publicado

2006-02-15

·

Atualizado

2017-07-20

·

CVE-2006-0712

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Squishdot versions 1.5.0 and earlier
Description The issue concerns a problem with the mail html template where it does not properly validate the email and title variables. This allows remote attackers to bypass spam filters by injecting SMTP headers, likely due to a CRLF injection vulnerability.
Recommendations For Squishdot versions 1.5.0 and earlier, as a temporary workaround, consider validating the email and title variables to prevent CRLF injection. Restrict access to the mail html template to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0712

Produtos afetados

Squishdot