Vulnerability Details CVE-2002-2109
Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.6%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2002-2109
-
cpe:2.3:a:matt_wright:formmail:1.0
-
cpe:2.3:a:matt_wright:formmail:1.1
-
cpe:2.3:a:matt_wright:formmail:1.2
-
cpe:2.3:a:matt_wright:formmail:1.3
-
cpe:2.3:a:matt_wright:formmail:1.4
-
cpe:2.3:a:matt_wright:formmail:1.5
-
cpe:2.3:a:matt_wright:formmail:1.6
-
cpe:2.3:a:matt_wright:formmail:1.7
-
cpe:2.3:a:matt_wright:formmail:1.8
-
cpe:2.3:a:matt_wright:formmail:1.9