CVE

Id
4882  
CVE No.
CVE-2002-0490  
Status
Entry  
Description
Instant Web Mail before 0.60 does not properly filter CR/LF sequences, which allows remote attackers to (1) execute arbitrary POP commands via the id parameter in message.php, or (2) modify certain mail message headers via numerous parameters in write.php.  
Phase
 
Votes
 
Comments