PT-2005-3719 · Thesitewizard.Com · Chfeedback.Pl Feedback Form Perl Script
Published
2005-09-08
·
Updated
2008-09-05
·
CVE-2005-2854
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
thesitewizard.com chfeedback.pl Feedback Form Perl Script version 2.0.1
Description
A CRLF injection issue exists, allowing remote attackers to use the script as a mail relay via CRLF sequences in the
name or email fields, which are injected into mail headers.Recommendations
For thesitewizard.com chfeedback.pl Feedback Form Perl Script version 2.0.1, consider validating and sanitizing user input in the
name and email fields to prevent CRLF injection. As a temporary workaround, restrict access to the script until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Chfeedback.Pl Feedback Form Perl Script