MIT cgiemail 1.6

CPE Details

MIT cgiemail 1.6
1.6
2007-08-23
19h16 +00:00
2007-09-14
15h36 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:mit:cgiemail:1.6:*:*:*:*:*:*:*

Informations

Vendor

mit

Product

cgiemail

Version

1.6

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2002-1652 2005-03-28 03h00 +00:00 Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long query parameter.
7.5
CVE-2002-1575 2004-02-11 04h00 +00:00 cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, BCC, and other header fields in the generated email message.
5