7.5

CVE-2002-2109

Exploit

Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Matt WrightFormmail Version1.0
Matt WrightFormmail Version1.1
Matt WrightFormmail Version1.2
Matt WrightFormmail Version1.3
Matt WrightFormmail Version1.4
Matt WrightFormmail Version1.5
Matt WrightFormmail Version1.6
Matt WrightFormmail Version1.7
Matt WrightFormmail Version1.8
Matt WrightFormmail Version1.9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.659
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P