Unrated severityNVD Advisory· Published May 8, 2009· Updated Jun 16, 2026
CVE-2009-1591
CVE-2009-1591
Description
CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04 allows remote attackers to inject arbitrary HTTP headers, and conduct cross-site scripting (XSS) or HTTP response splitting attacks, via CRLF sequences in an unspecified web form.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:cgi_rescue:cgi_web_mailer:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cgi_rescue:cgi_web_mailer:*:*:*:*:*:*:*:*range: <=1.03
- (no CPE)range: <1.04
Patches
Vulnerability mechanics
References
5- jvn.jp/en/jp/JVN28020230/index.htmlnvdPatch
- www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20090209180123nvdPatchVendor Advisory
- secunia.com/advisories/34862nvdVendor Advisory
- jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000024.htmlnvd
- www.securityfocus.com/bid/35047nvd
News mentions
0No linked articles in our index yet.