Lucene search

K
freebsdFreeBSD62B8F253-12D9-11DC-A35C-001485AB073E
HistoryFeb 21, 2007 - 12:00 a.m.

typo3 -- email header injection

2007-02-2100:00:00
vuxml.freebsd.org
10

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.005

Percentile

77.5%

Olivier Dobberkau, Andreas Otto, and Thorsten Kahler report:

An unspecified error in the internal form engine can be used for
sending arbitrary mail headers, using it for purposes which it
is not meant for, e.g. sending spam messages.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchtypo3< 4.0.5UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.005

Percentile

77.5%

Related for 62B8F253-12D9-11DC-A35C-001485AB073E