MEDIUM
CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy
Published Mar 14, 2006
5.0
MEDIUMCVSS 2.0
EPSS 2.92%
Description
CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (10)
- http://drupal.org/node/53806 x_refsource_CONFIRMPatchVendor Advisory
- http://secunia.com/advisories/19245 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19257 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/579 third-party-advisoryx_refsource_SREASON
- http://www.debian.org/security/2006/dsa-1007 vendor-advisoryx_refsource_DEBIAN
- http://www.osvdb.org/23912 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/427591/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/17104 vdb-entryx_refsource_BID
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-1229 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25206 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://drupal.org/node/53806 | x_refsource_CONFIRMPatchVendor Advisory | |
| http://secunia.com/advisories/19245 | third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory | |
| http://secunia.com/advisories/19257 | third-party-advisoryx_refsource_SECUNIA | |
| http://securityreason.com/securityalert/579 | third-party-advisoryx_refsource_SREASON | |
| http://www.debian.org/security/2006/dsa-1007 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.osvdb.org/23912 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/archive/1/427591/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/17104 | vdb-entryx_refsource_BID | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-1229 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/25206 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 14, 2006
Updated Aug 7, 2024
Reserved Mar 14, 2006
Link CVE-2006-1225
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-1229 Assigner mitre
Published Mar 14, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-1229