Vulnerability Details CVE-2006-0630
RITLabs The Bat! before 3.0.0.15 displays certain important headers from encapsulated data in message/partial MIME messages, instead of the real headers, which is in violation of RFC2046 header merging rules and allows remote attackers to spoof the origin of e-mail by sending a fragmented message, as demonstrated using spoofed Received: and Message-ID: headers.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.3%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2006-0630
-
cpe:2.3:a:ritlabs:the_bat:3.0
-
cpe:2.3:a:ritlabs:the_bat:3.0.0.10
-
cpe:2.3:a:ritlabs:the_bat:3.0.0.11
-
cpe:2.3:a:ritlabs:the_bat:3.0.0.12
-
cpe:2.3:a:ritlabs:the_bat:3.0.0.14
-
cpe:2.3:a:ritlabs:the_bat:3.0.0.7
-
cpe:2.3:a:ritlabs:the_bat:3.0.0.8
-
cpe:2.3:a:ritlabs:the_bat:3.0.0.9