Alexandria / SourceForge CRLF Injection Vulnerability
BID:7224
Info
Alexandria / SourceForge CRLF Injection Vulnerability
| Bugtraq ID: | 7224 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2003 12:00AM |
| Updated: | Mar 28 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Ulf Harnhammar. |
| Vulnerable: |
VA Software SourceForge Enterprise Edition 2.7 VA Software SourceForge Enterprise Edition 2.5 Alexandria Alexandria 2.5 Alexandria Alexandria 2.0 |
| Not Vulnerable: |
VA Software SourceForge Enterprise Edition 3.2 |
Discussion
Alexandria / SourceForge CRLF Injection Vulnerability
A vulnerability has been reported for Alexandria that may allow remote attackers to use the Alexandria system for proxying of unsolicited e-mail. The vulnerability exists in the 'sendmessage.php' script file.
There is no input validation performed on user-supplied data passed to functions in the 'sendmessage.php' script file. As a result, malicious users may embed CR/LF sequences to inject additional headers into outgoing messages.
Attackers may exploit this weakness to manipulate the structure of outgoing messages to send unsolicited e-mail to unsuspecting users.
A vulnerability has been reported for Alexandria that may allow remote attackers to use the Alexandria system for proxying of unsolicited e-mail. The vulnerability exists in the 'sendmessage.php' script file.
There is no input validation performed on user-supplied data passed to functions in the 'sendmessage.php' script file. As a result, malicious users may embed CR/LF sequences to inject additional headers into outgoing messages.
Attackers may exploit this weakness to manipulate the structure of outgoing messages to send unsolicited e-mail to unsuspecting users.
Exploit / POC
Alexandria / SourceForge CRLF Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Alexandria / SourceForge CRLF Injection Vulnerability
Solution:
Alexandria is no longer being actively maintained however, VA Software's SourceForge Enterprise Edition is believed to be invulnerable to this issue.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Alexandria is no longer being actively maintained however, VA Software's SourceForge Enterprise Edition is believed to be invulnerable to this issue.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Alexandria / SourceForge CRLF Injection Vulnerability
References:
References:
- Alexandria-dev (SourceForge)
- Alexandria-dev / sourceforge multiple vulnerabilities (Secunia Security Advisories
) - VA Software Products (VA Software)