7.5
CVSSv2

CVE-2008-1992

Published: 27/04/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3) default_mail_jmail.asp, which allows remote malicious users to bypass restrictions and relay email messages with modified From, FromName, and To fields.

Vulnerable Product Search on Vulmon Subscribe to Product

acidcat acidcat cms 3.4.1

Exploits

########################## wwwBugReportir ####################################### # # AmnPardaz Security Research Team # # Title: Acidcat CMS Multiple Vulnerabilities # Vendor: wwwacidcatcom # Vulnerable Version: 341 # Exploit: Available # Impact: High # Fix: N/A # Original Advisory: bugreportir/indexphp?/36 ################### ...