5
CVSSv2

CVE-2006-0712

Published: 15/02/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

mail_html template in Squishdot 1.5.0 and previous versions does not properly validate the (1) email and (2) title variables, which allows remote malicious users to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

squishdot squishdot 1.0.0

squishdot squishdot 1.1.0

squishdot squishdot 1.2.1

squishdot squishdot 1.4.0

squishdot squishdot 1.4.1

squishdot squishdot 1.5.0

squishdot squishdot 0.7.2