CVE-2007-1898: Medium severity Apple iOS and macOS vulnerability
Published May 16, 2007
·Updated
formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, SETTINGS[allowedemailhosts][], and subject parameters.
Affected Software
16 affected components
Apple iOS and macOS
HP HP-UX
HP Tru64
Linux Linux kernel
Microsoft Windows 2000
Microsoft Windows 2003 Server
Microsoft Windows 95
Microsoft Windows 98=gold
Microsoft Windows 98SE
Microsoft Windows Me
Microsoft Windows NT=4.0
Microsoft Windows XP
Santa Cruz Operation Sco Unix
Sun Solaris
Windriver Bsdos
Jetbox Jetbox CMS=2.1
Event History
May 16, 2007
CVE Published
10:30 PM
Data Sourced
10:30 PM
DescriptionWeaknessAffected Software
May 17, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1898?
CVE-2007-1898 is considered a medium severity vulnerability as it allows remote attackers to send arbitrary emails.
2
What systems are affected by CVE-2007-1898?
CVE-2007-1898 specifically affects Jetbox CMS version 2.1.
3
How do I fix CVE-2007-1898?
To fix CVE-2007-1898, you should upgrade Jetbox CMS to a newer, secure version that does not contain this vulnerability.
4
What type of attack is possible with CVE-2007-1898?
CVE-2007-1898 allows attackers to exploit the application to send spam emails by manipulating the recipient and subject parameters.
5
Is CVE-2007-1898 remotely exploitable?
Yes, CVE-2007-1898 can be remotely exploited by attackers to send unwanted emails through the vulnerable application.