CVE-2002-1575

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/03/2004
Last modified:
03/04/2025

Description

cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, BCC, and other header fields in the generated email message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mit:cgiemail:1.6:*:*:*:*:*:*:*