CVE-2008-1992
CVE-2008-1992
Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3) default_mail_jmail.asp, which allows remote attackers to bypass restrictions and relay email messages with modified From, FromName, and To fields.
Affected products
n/a · n/apublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/5478unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://bugreport.ir/index.php?/36http://secunia.com/advisories/29916http://securityreason.com/securityalert/3842https://exchange.xforce.ibmcloud.com/vulnerabilities/41921https://www.exploit-db.com/exploits/5478http://www.securityfocus.com/archive/1/491129/100/0/threadedhttp://www.securityfocus.com/bid/28868