VYPR
Unrated severityNVD Advisory· Published May 8, 2009· Updated Jun 16, 2026

CVE-2009-1591

CVE-2009-1591

Description

CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04 allows remote attackers to inject arbitrary HTTP headers, and conduct cross-site scripting (XSS) or HTTP response splitting attacks, via CRLF sequences in an unspecified web form.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:cgi_rescue:cgi_web_mailer:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cgi_rescue:cgi_web_mailer:*:*:*:*:*:*:*:*range: <=1.03
    • (no CPE)range: <1.04

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.