Logo des Repositoriums
 

E-mail Header Injection Vulnerabilities

dc.contributor.authorChandramouli, Sai Prashanth
dc.contributor.authorZhao, Ziming
dc.contributor.authorDoupé, Adam
dc.contributor.authorAhn, Gail-Joon
dc.date.accessioned2018-04-13T09:16:45Z
dc.date.available2018-04-13T09:16:45Z
dc.date.issued2017
dc.description.abstractE-mail Header Injection vulnerability is a class of vulnerability that can occur in web applications that use user input to construct e-mail messages. E-mail Header Injection is possible when the mailing script fails to check for the presence of e-mail headers in user input (either form fields or URL parameters). The vulnerability exists in the reference implementation of the built-in mail functionality in popular languages such as PHP, Java, Python, and Ruby. With the proper injection string, this vulnerability can be exploited to inject additional headers, modify existing headers, and alter the content of the e-mail.en
dc.identifier.doi10.1515/itit-2016-0039
dc.identifier.pissn1611-2776
dc.identifier.urihttps://dl.gi.de/handle/20.500.12116/16403
dc.language.isoen
dc.publisherDe Gruyter
dc.relation.ispartofit - Information Technology: Vol. 59, No. 5
dc.subjectE-mail Header Injection
dc.subject software security
dc.titleE-mail Header Injection Vulnerabilitiesen
dc.typeText/Journal Article
gi.citation.publisherPlaceBerlin
gi.citation.startPage67
gi.conference.sessiontitleThematic Issue: Vulnerability Analysis

Dateien