First published: Fri Mar 03 2017(Updated: )
cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cgiecho | ||
Cpanel Cgiemail |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5615 is rated as a medium severity vulnerability due to its potential for HTTP header injection.
To fix CVE-2017-5615, update your Cpanel Cgiemail and Cgiecho to the latest patched versions.
CVE-2017-5615 can facilitate remote attackers to inject malicious HTTP headers that may lead to session hijacking or other exploits.
CVE-2017-5615 affects specific versions of Cpanel Cgiemail and Cgiecho that do not protect against newline character injection.
Yes, CVE-2017-5615 can be exploited by remote attackers without the need for authentication.