Drupal Core 4.6.x Mail Header Injection
Drupal Core is prone to a mail header injection vulnerability. Exploiting this issue could allow an attacker to use a vulnerable Drupal site to send unwanted emails. Drupal Core versions 4.6.x ranging from 4.6.0 and up to and including 4.6.5 are vulnerable.