CVE-2002-2109: High severity Matt Wright FormMail vulnerability
Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTPREFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2109?
CVE-2002-2109 has a high severity rating due to the ability of attackers to bypass security checks and conduct unauthorized activities.
How do I fix CVE-2002-2109?
To fix CVE-2002-2109, upgrade to a newer version of Matt Wright FormMail that addresses this vulnerability.
Which versions of Matt Wright FormMail are affected by CVE-2002-2109?
CVE-2002-2109 affects all versions of Matt Wright FormMail up to and including version 1.9.
What type of exploitation is possible with CVE-2002-2109?
Exploitation of CVE-2002-2109 allows attackers to send unauthorized emails by spoofing or omitting the HTTP_REFERER header.
Is CVE-2002-2109 common in web applications?
CVE-2002-2109 highlights common vulnerabilities where referer checks are insufficiently enforced, which can be prevalent in many web applications.