CVE Database
/

CVE-2009-1469

Back to search

CVE-2009-1469

Published: May 5, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes it easier for remote attackers to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header in the subject element of an XML document, as demonstrated by triggering an e-mail message from the server that contains a user's correct credentials, and requests that the user compose a reply that includes this message.

VendorProductVersions

n/a

n/a

affected
n/a

References

54229
vdb-entry
x_refsource_OSVDB
34827
vdb-entry
x_refsource_BID
ADV-2009-1253
vdb-entry
x_refsource_VUPEN
1022166
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now