CVE-2002-2109
Published Dec 31, 2002
Last updated 16 years ago
Overview
- Description
- Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:matt_wright:formmail:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E030BDBE-4B0F-4FE1-8115-93E5ACEC591A" }, { "criteria": "cpe:2.3:a:matt_wright:formmail:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2012B4FA-7A4A-4AFF-8961-2A2750B9642B" }, { "criteria": "cpe:2.3:a:matt_wright:formmail:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8B21721-890E-498E-92F9-49C080070F45" }, { "criteria": "cpe:2.3:a:matt_wright:formmail:1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "41978011-ADC9-4F22-B2E9-7C45945BCDF5" }, { "criteria": "cpe:2.3:a:matt_wright:formmail:1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1480C519-2325-427E-B394-2832430F611C" }, { "criteria": "cpe:2.3:a:matt_wright:formmail:1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23BF8E39-98A9-4950-91EE-B4F4EAF7FA27" }, { "criteria": "cpe:2.3:a:matt_wright:formmail:1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B565A52D-EA07-4603-91B7-0105E632A2EC" }, { "criteria": "cpe:2.3:a:matt_wright:formmail:1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C2CA3226-1F70-49A3-8415-2861C82DAF42" }, { "criteria": "cpe:2.3:a:matt_wright:formmail:1.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E078DE78-8DD0-42F8-9E58-C7DBDB02DB60" }, { "criteria": "cpe:2.3:a:matt_wright:formmail:1.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1301D169-6E80-4917-AD54-9F4F4D3874CA" } ], "operator": "OR" } ] } ]