CVE-2006-0631

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/02/2006
Last modified:
03/04/2025

Description

CRLF injection vulnerability in mailback.pl in Erik C. Thauvin mailback allows remote attackers to use mailback as a "spam proxy" by modifying mail headers, including recipient e-mail addresses, via newline characters in the Subject field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:erik_c._thauvin:mailback:*:*:*:*:*:*:*:*