Back

CVE-2002-1917

CRLF injection vulnerability in the "User Profile: Send Email" feature in Geeklog 1.35 and 1.3.5sr1 allows remote attackers to obtain e-mail addresses by injecting a CRLF into the Subject field and adding a BCC mail header.

Published: Dec 31, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
geeklog geeklog 1.3.5_sr1
geeklog geeklog 1.35

GitHub Security Advisory GHSA-jwqr-9pxx-7hrc

CRLF injection vulnerability in the "User Profile: Send Email" feature in Geeklog 1.35 and 1.3...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 1.41%

Top 30% most likely to be exploited

Threat Score 20.4 / 100

Data Sources

NVD EPSS GitHub