Vulnerability Description
CRLF injection vulnerability in CGI-Rescue Mail F/W System (formd) before 8.3 allows remote attackers to spoof e-mails and inject e-mail headers via unspecified vectors in (1) mail.cgi and (2) query.cgi.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cgi-Rescue | Mail F W System | 8.3 |
References
- http://jvn.jp/jp/JVN%2311048526/index.htmlPatch
- http://secunia.com/advisories/21543PatchVendor Advisory
- http://www.osvdb.org/28131Patch
- http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20060822210549Patch
- http://www.securityfocus.com/bid/19676Patch
- http://www.vupen.com/english/advisories/2006/3359
- http://jvn.jp/jp/JVN%2311048526/index.htmlPatch
- http://secunia.com/advisories/21543PatchVendor Advisory
- http://www.osvdb.org/28131Patch
- http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20060822210549Patch
- http://www.securityfocus.com/bid/19676Patch
- http://www.vupen.com/english/advisories/2006/3359
FAQ
What is CVE-2006-4344?
CVE-2006-4344 is a vulnerability with a CVSS score of 5.0 (MEDIUM). CRLF injection vulnerability in CGI-Rescue Mail F/W System (formd) before 8.3 allows remote attackers to spoof e-mails and inject e-mail headers via unspecified vectors in (1) mail.cgi and (2) query.c...
How severe is CVE-2006-4344?
CVE-2006-4344 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-4344?
Check the references section above for vendor advisories and patch information. Affected products include: Cgi-Rescue Mail F W System.