5
CVSSv2

CVE-2009-4417

Published: 24/12/2009 Updated: 28/12/2009
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent malicious users to send arbitrary e-mail messages to any recipient address via vectors related to "events not yet mailed."

Vulnerable Product Search on Vulmon Subscribe to Product

zend framework

zend framework 1.9.4

zend framework 1.9.0

zend framework 1.8.3

zend framework 1.8.2

zend framework 1.8.1

zend framework 1.8.0

zend framework 1.6.0

zend framework 1.0.0

zend framework 0.9.3

zend framework 1.7.7

zend framework 1.7.0

zend framework 1.6.2

zend framework 1.5.2

zend framework 1.5.0

zend framework 1.0.4

zend framework 1.0.2

zend framework 0.9.2

zend framework 0.9.0

zend framework 0.1.3

zend framework 1.9.2

zend framework 1.9.1

zend framework 1.7.5

zend framework 1.7.4

zend framework 1.7.3

zend framework 1.7.2

zend framework 0.7.0

zend framework 0.6.0

zend framework 0.2.0

zend framework 0.1.5

zend framework 1.9

zend framework 1.9.5

zend framework 1.9.3

zend framework 1.8.4

zend framework 1.7.8

zend framework 1.7.6

zend framework 1.7.1

zend framework 1.6.1

zend framework 1.5.3

zend framework 1.5.1

zend framework 1.0.3

zend framework 1.0.1

zend framework 0.9.1

zend framework 0.8.0

zend framework 0.1.4