Squishdot Mail_HTML CRLF Injection Vulnerability
BID:16667
Info
Squishdot Mail_HTML CRLF Injection Vulnerability
| Bugtraq ID: | 16667 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2006 12:00AM |
| Updated: | Feb 15 2006 11:02PM |
| Credit: | Garikoitz Araolaza is credited with the discovery of this vulnerability. |
| Vulnerable: |
Squishdot Squishdot 1.5 |
| Not Vulnerable: | |
Discussion
Squishdot Mail_HTML CRLF Injection Vulnerability
Squishdot is prone to a CRLF-injection vulnerability.
Attackers may exploit this vulnerability to modify email headers and manipulate the structure of outgoing messages. For example, attackers may be able to set the recipient to an arbitrary value.
Version 1.5 is vulnerable; other versions may also be affected.
Squishdot is prone to a CRLF-injection vulnerability.
Attackers may exploit this vulnerability to modify email headers and manipulate the structure of outgoing messages. For example, attackers may be able to set the recipient to an arbitrary value.
Version 1.5 is vulnerable; other versions may also be affected.
Exploit / POC
Squishdot Mail_HTML CRLF Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Squishdot Mail_HTML CRLF Injection Vulnerability
Solution:
The vendor has released a patch to address this issue; please see the reference section for further details.
Squishdot Squishdot 1.5
Solution:
The vendor has released a patch to address this issue; please see the reference section for further details.
Squishdot Squishdot 1.5
-
Squishdot Squishdot_mail_html.dtml
Patch for Squishdot 1.5
http://www.squishdot.org/1139510883/Squishdot_mail_html.dtml
References
Squishdot Mail_HTML CRLF Injection Vulnerability
References:
References:
- Small Spam Vulnerability in Squishdot (SquishDot)
- SquishDot Web Site (SquishDot)