CVE-2009-1591
08.05.2009, 18:30
CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04 allows remote attackers to inject arbitrary HTTP headers, and conduct cross-site scripting (XSS) or HTTP response splitting attacks, via CRLF sequences in an unspecified web form.
Vendor | Product | Version |
---|---|---|
cgi_rescue | cgi_web_mailer | 𝑥 ≤ 1.03 |
𝑥
= Vulnerable software versions
References