Back

CVE-2005-2854

CRLF injection vulnerability in thesitewizard.com chfeedback.pl Feedback Form Perl Script 2.0.1 allows remote attackers to use the script as a mail relay (spam proxy) via CRLF sequences in the (1) name or (2) email fields, which are injected into mail headers.

Published: Sep 8, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
thesitewizard.com chfeedback.pl_feedback_form_perl_script 2.0.1

GitHub Security Advisory GHSA-8v3f-v4gp-j935

CRLF injection vulnerability in thesitewizard.com chfeedback.pl Feedback Form Perl Script 2.0.1...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 1.07%

Top 38% most likely to be exploited

Threat Score 20.3 / 100

Data Sources

NVD EPSS GitHub