First published: Wed May 16 2007(Updated: )
formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | ||
HPE HP-UX | ||
Compaq Tru64 | ||
Linux Kernel | ||
Microsoft Windows 2000 | ||
Microsoft Windows Server 2003 | ||
Microsoft Windows 9x | ||
Microsoft Windows 9x | =gold | |
Microsoft Windows 98 | ||
Microsoft Windows | ||
Microsoft Windows NT | =4.0 | |
Microsoft Windows XP | ||
SCO UNIX | ||
Oracle Solaris and Zettabyte File System (ZFS) | ||
Wind River BSD OS | ||
Jetbox One CMS | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1898 is considered a medium severity vulnerability as it allows remote attackers to send arbitrary emails.
CVE-2007-1898 specifically affects Jetbox CMS version 2.1.
To fix CVE-2007-1898, you should upgrade Jetbox CMS to a newer, secure version that does not contain this vulnerability.
CVE-2007-1898 allows attackers to exploit the application to send spam emails by manipulating the recipient and subject parameters.
Yes, CVE-2007-1898 can be remotely exploited by attackers to send unwanted emails through the vulnerable application.