{"api_version":"1","generated_at":"2026-07-23T10:47:49+00:00","cve":"CVE-2009-1777","urls":{"html":"https://cve.report/CVE-2009-1777","api":"https://cve.report/api/cve/CVE-2009-1777.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-1777","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-1777"},"summary":{"title":"CVE-2009-1777","description":"CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the redirect parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-05-22 20:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/34929","name":"http://www.securityfocus.com/bid/34929","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Matt Wright FormMail HTTP Response Splitting and Cross Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.ush.it/team/ush/hack-formmail_192/adv.txt","name":"http://www.ush.it/team/ush/hack-formmail_192/adv.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"302 Found","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/503446/100/0/threaded","name":"http://www.securityfocus.com/archive/1/503446/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/35068","name":"http://secunia.com/advisories/35068","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Matt Wright FormMail Cross-Site Scripting and HTTP Response Splitting - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-1777","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1777","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"1777","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"matt_wright","cpe5":"formmail","cpe6":"1.92","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:27:54.764Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.ush.it/team/ush/hack-formmail_192/adv.txt"},{"name":"20090512 FormMail 1.92 Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/503446/100/0/threaded"},{"name":"34929","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/34929"},{"name":"35068","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35068"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-05-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the redirect parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.ush.it/team/ush/hack-formmail_192/adv.txt"},{"name":"20090512 FormMail 1.92 Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/503446/100/0/threaded"},{"name":"34929","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/34929"},{"name":"35068","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35068"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-1777","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the redirect parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.ush.it/team/ush/hack-formmail_192/adv.txt","refsource":"MISC","url":"http://www.ush.it/team/ush/hack-formmail_192/adv.txt"},{"name":"20090512 FormMail 1.92 Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/503446/100/0/threaded"},{"name":"34929","refsource":"BID","url":"http://www.securityfocus.com/bid/34929"},{"name":"35068","refsource":"SECUNIA","url":"http://secunia.com/advisories/35068"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-1777","datePublished":"2009-05-22T20:00:00.000Z","dateReserved":"2009-05-22T00:00:00.000Z","dateUpdated":"2024-08-07T05:27:54.764Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-05-22 20:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:matt_wright:formmail:1.92:*:*:*:*:*:*:*","matchCriteriaId":"45929A3B-C4BF-4E62-8F04-BA3A42960EE4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"1777","Ordinal":"1","Title":"CVE-2009-1777","CVE":"CVE-2009-1777","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"1777","Ordinal":"1","NoteData":"CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the redirect parameter.","Type":"Description","Title":"CVE-2009-1777"},{"CveYear":"2009","CveId":"1777","Ordinal":"2","NoteData":"2009-05-22","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"1777","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}