CVE-2002-0490
Instant Web Mail before 0.60 does not properly filter CR/LF sequences, which allows remote attackers to (1) execute arbitrary POP commands via the id parameter in message.php, or (2) modify certain mail message headers via numerous parameters in write.php.
Scoring
- CVSS base score
- 0.09
- EPSS probability
- 2.26%
- Published
- 2003-04-02
- Last modified
- 2026-03-16
Affected products
- n/a n/a