CVE-2006-4624

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
07/09/2006
Last modified:
03/04/2025

Description

CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:mailman:*:*:*:*:*:*:*:* 2.1.8 (including)


References to Advisories, Solutions, and Tools