Webbler CMS Mail A Friend Open Email Relay Vulnerability
BID:25045
Info
Webbler CMS Mail A Friend Open Email Relay Vulnerability
| Bugtraq ID: | 25045 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2007 12:00AM |
| Updated: | Jul 26 2007 10:15PM |
| Credit: | Adrian Pastor is credited with the discovery of this issue. |
| Vulnerable: |
tincan ltd Webbler CMS 3.1.3 |
| Not Vulnerable: |
tincan ltd Webbler CMS 3.1.6 |
Discussion
Webbler CMS Mail A Friend Open Email Relay Vulnerability
The 'webbler' is prone to an open-email-relay vulnerability.
An attacker may leverage the issue to use webservers that are hosting the vulnerable software to send arbitrary unsolicited bulk email. Attackers may also forge email messages that originate from trusted mail servers.
This issue affects webbler 3.1.3; prior versions may also be affected.
The 'webbler' is prone to an open-email-relay vulnerability.
An attacker may leverage the issue to use webservers that are hosting the vulnerable software to send arbitrary unsolicited bulk email. Attackers may also forge email messages that originate from trusted mail servers.
This issue affects webbler 3.1.3; prior versions may also be affected.
Exploit / POC
Webbler CMS Mail A Friend Open Email Relay Vulnerability
An attacker can use a browser to exploit this issue.
The following proof-of-concept is available:
An attacker can use a browser to exploit this issue.
The following proof-of-concept is available:
Solution / Fix
Webbler CMS Mail A Friend Open Email Relay Vulnerability
Solution:
The vendor released an update to address these issues. Please see the references for more information.
Solution:
The vendor released an update to address these issues. Please see the references for more information.
References
Webbler CMS Mail A Friend Open Email Relay Vulnerability
References:
References: