Vulnerability Details CVE-2002-1771
Matt Wright FormMail 1.9 and earlier allows remote attackers to send spam or anonymous e-mail by injecting a newline character followed by CC:, BCC:, or additional TO: fields in the email and realname CGI variables.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.4%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2002-1771
-
cpe:2.3:a:matt_wright:formmail:1.0
-
cpe:2.3:a:matt_wright:formmail:1.1
-
cpe:2.3:a:matt_wright:formmail:1.2
-
cpe:2.3:a:matt_wright:formmail:1.3
-
cpe:2.3:a:matt_wright:formmail:1.4
-
cpe:2.3:a:matt_wright:formmail:1.5
-
cpe:2.3:a:matt_wright:formmail:1.6
-
cpe:2.3:a:matt_wright:formmail:1.7
-
cpe:2.3:a:matt_wright:formmail:1.8
-
cpe:2.3:a:matt_wright:formmail:1.9