VulnerabilityModified
CVE-2006-0712
mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.
MEDIUM 5.0EPSS 1.61%
Does this matter?
Lower severity and a low EPSS score (1.61%). Track it; it rarely justifies an emergency change on its own.
Description
mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.61% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- squishdot/squishdot
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/18868
- http://www.securityfocus.com/bid/16667
- http://www.squishdot.org/1139510883
- http://www.vupen.com/english/advisories/2006/0551
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24659
- http://secunia.com/advisories/18868
- http://www.securityfocus.com/bid/16667
- http://www.squishdot.org/1139510883
- http://www.vupen.com/english/advisories/2006/0551
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24659
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.