Vulnerability Name:

CVE-2002-1575 (CCN-9361)

Assigned:2002-06-14
Published:2002-06-14
Updated:2017-07-11
Summary:cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, BCC, and other header fields in the generated email message.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: BugTraq Mailing List, Fri Jun 14 2002 - 09:20:55 CDT
Another cgiemail bug

Source: MITRE
Type: CNA
CVE-2002-1575

Source: BUGTRAQ
Type: UNKNOWN
20020614 Another cgiemail bug

Source: BUGTRAQ
Type: UNKNOWN
20031003 patch for vulnerability in cgiemail

Source: DEBIAN
Type: Patch, Vendor Advisory
DSA-437

Source: DEBIAN
Type: DSA-437
cgiemail -- open mail relay

Source: CCN
Type: OSVDB ID: 3955
cgiemail Open E-Mail Relay

Source: BID
Type: Patch, Vendor Advisory
5013

Source: CCN
Type: BID-5013
MIT CGIEmail Arbitrary Recipient Mail Relay Vulnerability

Source: XF
Type: UNKNOWN
cgiemail-open-mail-relay(9361)

Source: XF
Type: UNKNOWN
cgiemail-open-mail-relay(9361)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mit:cgiemail:1.6:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:mit:cgiemail:1.6:*:*:*:*:*:*:*
  • AND
  • cpe:/o:debian:debian_linux:3.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.debian:def:437
    V
    open mail relay
    2004-02-11
    BACK
    mit cgiemail 1.6
    mit cgiemail 1.6
    debian debian linux 3.0