7.5

CVE-2002-2109

Exploit

Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer.

Data is provided by the National Vulnerability Database (NVD)
Matt WrightFormmail Version1.0
Matt WrightFormmail Version1.1
Matt WrightFormmail Version1.2
Matt WrightFormmail Version1.3
Matt WrightFormmail Version1.4
Matt WrightFormmail Version1.5
Matt WrightFormmail Version1.6
Matt WrightFormmail Version1.7
Matt WrightFormmail Version1.8
Matt WrightFormmail Version1.9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.52% 0.659
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P