CRLF injection vulnerability in mailback.pl in Erik C. Thauvin mailback allows remote attackers to use mailback as a "spam proxy" by modifying mail headers, including recipient e-mail addresses, via newline characters in the Subject field.
Link | Tags |
---|---|
http://seclists.org/lists/bugtraq/2006/Feb/0094.html | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24540 | vdb entry |
http://www.vupen.com/english/advisories/2006/0459 | vdb entry |
http://seclists.org/lists/bugtraq/2006/Feb/0154.html | exploit mailing list |
http://www.osvdb.org/22955 | patch vdb entry |
http://secunia.com/advisories/18748 | patch vendor advisory third party advisory |
http://vc.thauvin.net/cvs/cgi/mailback/mailback.pl?view=log |