models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.
- http://packetstormsecurity.com/files/129042/Anchor-CMS-0.9.2-Header-Injection.html
No PoCs found on GitHub currently.