PT-2005-3719 · Thesitewizard.Com · Chfeedback.Pl Feedback Form Perl Script

Published

2005-09-08

·

Updated

2008-09-05

·

CVE-2005-2854

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions thesitewizard.com chfeedback.pl Feedback Form Perl Script version 2.0.1
Description A CRLF injection issue exists, allowing remote attackers to use the script as a mail relay via CRLF sequences in the name or email fields, which are injected into mail headers.
Recommendations For thesitewizard.com chfeedback.pl Feedback Form Perl Script version 2.0.1, consider validating and sanitizing user input in the name and email fields to prevent CRLF injection. As a temporary workaround, restrict access to the script until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2854

Affected Products

Chfeedback.Pl Feedback Form Perl Script