Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-1225

CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 76.7%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2006-1225
  • Drupal » Drupal » Version: 4.5.0
    cpe:2.3:a:drupal:drupal:4.5.0
  • Drupal » Drupal » Version: 4.5.1
    cpe:2.3:a:drupal:drupal:4.5.1
  • Drupal » Drupal » Version: 4.5.2
    cpe:2.3:a:drupal:drupal:4.5.2
  • Drupal » Drupal » Version: 4.5.3
    cpe:2.3:a:drupal:drupal:4.5.3
  • Drupal » Drupal » Version: 4.6.0
    cpe:2.3:a:drupal:drupal:4.6.0
  • Drupal » Drupal » Version: 4.6.1
    cpe:2.3:a:drupal:drupal:4.6.1


Contact Us

Shodan ® - All rights reserved