CVE Database
/

CVE-2008-1992

Back to search

CVE-2008-1992

Published: Apr 27, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3) default_mail_jmail.asp, which allows remote attackers to bypass restrictions and relay email messages with modified From, FromName, and To fields.

VendorProductVersions

n/a

n/a

affected
n/a

References

3842
third-party-advisory
x_refsource_SREASON
29916
third-party-advisory
x_refsource_SECUNIA
20080420 Acidcat CMS Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
28868
vdb-entry
x_refsource_BID
5478
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now