PHP-Nuke CRLF Injection Vulnerability...

- AV AC AU C I A
发布: 2002-12-20
修订: 2025-04-13

Throughout PHP-Nuke, the PHP mail() function is implemented to handle email through web-based intefaces for various purposes (for features such as "feedback", "send this to a friend", etc). There is no input validation performed on user data passed to this function. As a result, malicious users may embed CR/LF sequences to inject additional headers into outgoing messages.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息