Matt Wright FormMail Cross-Site Request Forgery Vulnerability
BID:2080
Info
Matt Wright FormMail Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 2080 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 01 1997 12:00AM |
| Updated: | Jan 01 1997 12:00AM |
| Credit: | Discovery information is not currently known. |
| Vulnerable: |
Matt Wright FormMail 1.8 Matt Wright FormMail 1.7 Matt Wright FormMail 1.6 Matt Wright FormMail 1.5 Matt Wright FormMail 1.4 Matt Wright FormMail 1.3 Matt Wright FormMail 1.2 Matt Wright FormMail 1.1 Matt Wright FormMail 1.0 |
| Not Vulnerable: |
Matt Wright FormMail 1.9 |
Discussion
Matt Wright FormMail Cross-Site Request Forgery Vulnerability
FormMail is a widely-used web-based e-mail gateway, which allows form-based input to be emailed to a specified user.
A web server can use a remote site's FormMail script without authorization, using remote system resources or exploiting other vulnerabilities in the script. For example, this issue can be used to exploit BID 2079, "Matt Wright FormMail Remote Command Execution Vulnerability".
FormMail is a widely-used web-based e-mail gateway, which allows form-based input to be emailed to a specified user.
A web server can use a remote site's FormMail script without authorization, using remote system resources or exploiting other vulnerabilities in the script. For example, this issue can be used to exploit BID 2079, "Matt Wright FormMail Remote Command Execution Vulnerability".
Solution / Fix
Matt Wright FormMail Cross-Site Request Forgery Vulnerability
Solution:
The vendor has fixed this issue in FormMail 1.9. Users running previous versions are advised to upgrade.
Matt Wright FormMail 1.0
Matt Wright FormMail 1.1
Matt Wright FormMail 1.2
Matt Wright FormMail 1.3
Matt Wright FormMail 1.4
Matt Wright FormMail 1.5
Matt Wright FormMail 1.6
Matt Wright FormMail 1.7
Matt Wright FormMail 1.8
Solution:
The vendor has fixed this issue in FormMail 1.9. Users running previous versions are advised to upgrade.
Matt Wright FormMail 1.0
-
Matt Wright Formmail 1.9
http://www.worldwidemart.com/scripts/readme/formmail.shtml
Matt Wright FormMail 1.1
-
Matt Wright Formmail 1.9
http://www.worldwidemart.com/scripts/readme/formmail.shtml
Matt Wright FormMail 1.2
-
Matt Wright Formmail 1.9
http://www.worldwidemart.com/scripts/readme/formmail.shtml
Matt Wright FormMail 1.3
-
Matt Wright Formmail 1.9
http://www.worldwidemart.com/scripts/readme/formmail.shtml
Matt Wright FormMail 1.4
-
Matt Wright Formmail 1.9
http://www.worldwidemart.com/scripts/readme/formmail.shtml
Matt Wright FormMail 1.5
-
Matt Wright Formmail 1.9
http://www.worldwidemart.com/scripts/readme/formmail.shtml
Matt Wright FormMail 1.6
-
Matt Wright Formmail 1.9
http://www.worldwidemart.com/scripts/readme/formmail.shtml
Matt Wright FormMail 1.7
-
Matt Wright Formmail 1.9
http://www.worldwidemart.com/scripts/readme/formmail.shtml
Matt Wright FormMail 1.8
-
Matt Wright Formmail 1.9
http://www.worldwidemart.com/scripts/readme/formmail.shtml
References
Matt Wright FormMail Cross-Site Request Forgery Vulnerability
References:
References:
- FormMail Product Home Page (Matt Wright)
- FormMail remote usage (Internet Security Systems)
- Matt Wright FormMail Remote Command Execution Vulnerability (SecurityFocus)
- The Most Comprehensive List of CGI & httpd Bugs ([email protected])