5.8
CVSSv2

CVE-2007-1898

Published: 16/05/2007 Updated: 16/10/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

formmail.php in Jetbox CMS 2.1 allows remote malicious users to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

jetbox jetbox_cms 2.1

Exploits

source: wwwsecurityfocuscom/bid/23989/info Jetbox CMS is prone to an input-validation vulnerabilitiy because it fails to adequately sanitize user-supplied input Attackers can exploit this issue to send spam email in the context of the application Jetbox 21 is vulnerable; other versions may also be affected wwwexamplecom/[ ...
Jetbox CMS version 21 suffers from an e-mail injection vulnerability that allows for spamming ...