vendor:
Biz Mail Form
by:
SecurityFocus
7.5
CVSS
HIGH
Mail Relay Abuse
400
CWE
Product Name: Biz Mail Form
Affected Version From: Biz Mail Form 2.2
Affected Version To: Biz Mail Form 2.2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
Biz Mail Form Vulnerability
An attacker can exploit this issue to inject arbitrary SMTP headers by using CR and LF sequences. If successful, it becomes possible to abuse the application as a mail relay. Email may be sent to arbitrary computers. This could be exploited by spammers or other malicious parties.
Mitigation:
Update to the latest version of Biz Mail Form and ensure that all security patches are applied.