First published: Wed May 16 2007(Updated: )
formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | ||
HPE HP-UX | ||
HP Tru64 UNIX | ||
Linux Kernel | ||
Microsoft Windows 2000 | ||
Microsoft Windows 2003 Server | ||
Microsoft Windows 95 | ||
Microsoft Windows 98 | =gold | |
Microsoft Windows 98SE | ||
Microsoft Windows Me | ||
Microsoft Windows NT | =4.0 | |
Microsoft Windows XP | ||
santa cruz operation sco unix | ||
Oracle Solaris SPARC | ||
windriver bsdos | ||
Jetbox CMS | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1898 is considered a medium severity vulnerability as it allows remote attackers to send arbitrary emails.
CVE-2007-1898 specifically affects Jetbox CMS version 2.1.
To fix CVE-2007-1898, you should upgrade Jetbox CMS to a newer, secure version that does not contain this vulnerability.
CVE-2007-1898 allows attackers to exploit the application to send spam emails by manipulating the recipient and subject parameters.
Yes, CVE-2007-1898 can be remotely exploited by attackers to send unwanted emails through the vulnerable application.