vendor:
FormMail
by:
Francesco Ongaro, Giovanni Pellerano, Antonio Parata
4,3
CVSS
MEDIUM
Multiple Vulnerabilities in FormMail
N/A
CWE
Product Name: FormMail
Affected Version From: FormMail 1.92
Affected Version To: FormMail 1.93
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
20090511
FormMail 1.92 Multiple Vulnerabilities
Multiple Vulnerabilities exist in FormMail software. What follows is the code used to validate the user input: Line 283: $safeConfig array definition. Line 518: definition of clean_html. The clean_html function is used to sanitize the user input, but it is not enough to prevent Cross Site Scripting and HTTP Response Header Injection.
Mitigation:
Upgrade to FormMail 1.93 or later.