|
[Japanese]
|
JVNDB-2006-000624
|
CGI RESCUE WebFORM allows unauthorized email transmission
|
WebFORM from CGI RESCUE is software which delivers the HTML form inputs via email. WebFORM fails to check the mail headers properly, allowing a remote attacker to send email to arbitrary addresses.
According to the vendor's information, FORM2MAIL also contains a similar vulnerability, and the fixed version of FORM2MAIL is available.
|
Base Metrics:
5.0 (Medium)
[IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Partial
|
|
|
CGI RESCUE
- FORM2MAIL v1.21 and earlier
|
|
A remote attacker may send emails to arbitrary addresses.
|
|
CGI RESCUE
|
|
- CVE-2006-2944
|
- JVN : JVN#39570254
- National Vulnerability Database (NVD) : CVE-2006-2944
- Secunia Advisory : SA20515
- SecurityFocus : 18434
- FrSIRT Advisories : FrSIRT/ADV-2006-2234
|
[2008/05/21]
Web page published
|