PT-2006-1765 · Squishdot · Squishdot
Published
2006-02-15
·
Updated
2017-07-20
·
CVE-2006-0712
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Squishdot versions 1.5.0 and earlier
Description
The issue concerns a problem with the mail html template where it does not properly validate the
email and title variables. This allows remote attackers to bypass spam filters by injecting SMTP headers, likely due to a CRLF injection vulnerability.Recommendations
For Squishdot versions 1.5.0 and earlier, as a temporary workaround, consider validating the
email and title variables to prevent CRLF injection. Restrict access to the mail html template to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Squishdot