CVE-2002-1575
cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, BCC, and other header fields in the generated email message.
Scoring
- CVSS base score
- 0.03
- EPSS probability
- 0.75%
- Published
- 2004-02-11
- Last modified
- 2026-03-16
Affected products
- n/a n/a