CVE Database · CVE-2007-4612
CVSS v3.1
N/A
EPSS
1.07%
Published
Aug 31, 2007
Modified
Jun 16, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
CRLF injection vulnerability in contact.php in Moonware (aka Dale Mooney Gallery) allows remote attackers to add arbitrary mail headers via CRLF sequences in the subject parameter. NOTE: this can be leveraged for spam by adding To or Cc headers.
Weaknesses (CWE)
Affected Products (1)
References (8)