CVE-2007-2731: CRLF Injection
Published May 16, 2007
·Updated
CRLF injection vulnerability in formmail.php in Jetbox CMS 2.1 might allow remote attackers to inject arbitrary e-mail headers via LF (%0A) sequences in the subject parameter, a related issue to CVE-2007-1898.
Affected Software
1 affected component
Jetbox Jetbox CMS=2.1
Event History
May 16, 2007
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2731?
CVE-2007-2731 has been classified as a medium severity vulnerability due to its potential to allow arbitrary email header injection.
2
How do I fix CVE-2007-2731?
To fix CVE-2007-2731, it is recommended to upgrade Jetbox CMS to a version that is not vulnerable to CRLF injection.
3
What type of attack can exploit CVE-2007-2731?
CVE-2007-2731 can be exploited via CRLF injection, allowing attackers to manipulate email headers.
4
Which software is affected by CVE-2007-2731?
CVE-2007-2731 affects Jetbox CMS version 2.1 specifically.
5
What impact does CVE-2007-2731 have on email functionality?
CVE-2007-2731 can lead to unauthorized email header manipulation, potentially enabling spam or phishing attacks.