FormMail HTTP_Referer Spoofing Vulnerability
BID:3954
Info
FormMail HTTP_Referer Spoofing Vulnerability
| Bugtraq ID: | 3954 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2002 12:00AM |
| Updated: | Jan 23 2002 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on January 23rd, 2002 by "Ronald F. Guilmette" <[email protected]>. |
| Vulnerable: |
Matt Wright FormMail 1.9 Matt Wright FormMail 1.8 Matt Wright FormMail 1.7 Matt Wright FormMail 1.6 Matt Wright FormMail 1.5 Matt Wright FormMail 1.4 Matt Wright FormMail 1.3 Matt Wright FormMail 1.2 Matt Wright FormMail 1.1 Matt Wright FormMail 1.0 |
| Not Vulnerable: | |
Discussion
FormMail HTTP_Referer Spoofing Vulnerability
FormMail is a widely-used web-based e-mail gateway, which allows form-based input to be emailed to a specified user. It is written in Perl and will run on most Linux and Unix variants, in addition to Microsoft Windows operating systems.
FormMail relies on the HTTP_REFERER header to establish the identity of the user. Forged HTTP_REFERERS may circumvent the measures employed by FormMail to validate the authenticity of the user. It is trivial for a remote attacker to craft their own HTTP_REFERER header.
A remote attacker may take advantage of this issue to exploit other vulnerabilities, such as manipulating CGI variables to use the FormMail program as an anonymous e-mail relay for spamming/mailbombing purposes. For more information, refer to BugTraq ID 2469 "FormMail Recipient CGI Variable Spamming Vulnerability".
FormMail is a widely-used web-based e-mail gateway, which allows form-based input to be emailed to a specified user. It is written in Perl and will run on most Linux and Unix variants, in addition to Microsoft Windows operating systems.
FormMail relies on the HTTP_REFERER header to establish the identity of the user. Forged HTTP_REFERERS may circumvent the measures employed by FormMail to validate the authenticity of the user. It is trivial for a remote attacker to craft their own HTTP_REFERER header.
A remote attacker may take advantage of this issue to exploit other vulnerabilities, such as manipulating CGI variables to use the FormMail program as an anonymous e-mail relay for spamming/mailbombing purposes. For more information, refer to BugTraq ID 2469 "FormMail Recipient CGI Variable Spamming Vulnerability".
Solution / Fix
FormMail HTTP_Referer Spoofing Vulnerability
Solution:
A SourceForge project, entitled nms, has been started to serve as a repository for user-supplied replacements for various Matt Wright scripts. Users intent on using this software should investigate nms at the following URL:
http://nms-cgi.sourceforge.net/
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
A SourceForge project, entitled nms, has been started to serve as a repository for user-supplied replacements for various Matt Wright scripts. Users intent on using this software should investigate nms at the following URL:
http://nms-cgi.sourceforge.net/
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.