漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, BCC, and other header fields in the generated email message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MIT CGIEmail任意邮件接收中继漏洞
Vulnerability Description
cgiemail存在漏洞。远程攻击者可以借助回车换行向例如 "required-subject,"的参数中注入换行符(%0a)的编码字符。该漏洞可以用来修改抄送,密送以及其他邮件消息中的头字段。
CVSS Information
N/A
Vulnerability Type
N/A