5
CVSSv2

CVE-2005-2431

Published: 03/08/2005 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allows remote malicious users to send a large number of messages to arbitrary e-mail addresses (aka mail bomb).

Vulnerable Product Search on Vulmon Subscribe to Product

gforge gforge 4.5