Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.14224
Category:Web application abuses
Title:Simple Form Mail Relaying Vulnerability
Summary:The target is running at least one instance of Simple Form which fails; to validate the parameters 'admin_email_to' and 'admin_email_from'.
Description:Summary:
The target is running at least one instance of Simple Form which fails
to validate the parameters 'admin_email_to' and 'admin_email_from'.

Vulnerability Impact:
An attacker, exploiting this flaw, would be able to send email through
the server (utilizing the form) to any arbitrary recipient with any
arbitrary message content. In other words, the remote host can be
used as a mail relay for things like SPAM.

Solution:
Upgrade to Simple Form 2.2 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

CopyrightCopyright (C) 2004 George A. Theall

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.