Vulnerabilities > CVE-2002-1917 - Unspecified vulnerability in Geeklog 1.3.5Sr1/1.35
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
CRLF injection vulnerability in the "User Profile: Send Email" feature in Geeklog 1.35 and 1.3.5sr1 allows remote attackers to obtain e-mail addresses by injecting a CRLF into the Subject field and adding a BCC mail header.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |