Drupal Form_mail Module Multiple CRLF Injection Vulnerabilities
BID:18833
CVE-2006-3473 |Info
Drupal Form_mail Module Multiple CRLF Injection Vulnerabilities
| Bugtraq ID: | 18833 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3473 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2006 12:00AM |
| Updated: | Feb 11 2016 07:43AM |
| Credit: | The vendor reported these vulnerabilities. |
| Vulnerable: |
Drupal Drupal Form_mail 1.8.2.1 |
| Not Vulnerable: |
Drupal Drupal Form_mail 4.6 |
Discussion
Drupal Form_mail Module Multiple CRLF Injection Vulnerabilities
The Form_mail module for Drupal is prone to multiple CRLF-injection vulnerabilities.
Attackers may exploit these vulnerabilities to modify email headers and manipulate the structure of outgoing messages. For example, attackers may be able to set the recipient to an arbitrary value.
Revisions prior to 1.8.2.2 are vulnerable; other versions may also be affected.
These issues are related to one of the issues reported in BID 17104.
The Form_mail module for Drupal is prone to multiple CRLF-injection vulnerabilities.
Attackers may exploit these vulnerabilities to modify email headers and manipulate the structure of outgoing messages. For example, attackers may be able to set the recipient to an arbitrary value.
Revisions prior to 1.8.2.2 are vulnerable; other versions may also be affected.
These issues are related to one of the issues reported in BID 17104.
Exploit / POC
Drupal Form_mail Module Multiple CRLF Injection Vulnerabilities
This issue can be exploited through a web client.
This issue can be exploited through a web client.
Solution / Fix
Drupal Form_mail Module Multiple CRLF Injection Vulnerabilities
Solution:
The vendor has released version 4.6.0 to address this issue; please see the reference section for details.
Drupal Drupal Form_mail 1.8.2.1
Solution:
The vendor has released version 4.6.0 to address this issue; please see the reference section for details.
Drupal Drupal Form_mail 1.8.2.1
-
Drupal form_mail-4.6.0.tar.gz
http://ftp.osuosl.org/pub/drupal/files/projects/form_mail-4.6.0.tar.gz
References
Drupal Form_mail Module Multiple CRLF Injection Vulnerabilities
References:
References:
- Form_mail module allows arbitrary header injection (Drupal)
- Vendor Homepage (Drupal)