Page 2 of 21 results (0.004 seconds)

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 1

Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post. • http://archives.neohapsis.com/archives/bugtraq/2003-02/0274.html http://www.iss.net/security_center/static/11383.php http://www.securityfocus.com/bid/6918 •

CVSS: 5.0EPSS: 0%CPEs: 10EXPL: 0

Matt Wright FormMail 1.9 and earlier allows remote attackers to send spam or anonymous e-mail by injecting a newline character followed by CC:, BCC:, or additional TO: fields in the email and realname CGI variables. • http://archives.neohapsis.com/archives/bugtraq/2002-01/0307.html http://www.scriptarchive.com/readme/formmail.html#history http://www.securityfocus.com/bid/3955 https://exchange.xforce.ibmcloud.com/vulnerabilities/8013 •

CVSS: 7.5EPSS: 0%CPEs: 10EXPL: 1

Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer. • http://archives.neohapsis.com/archives/bugtraq/2002-01/0307.html http://worldwidemart.com/scripts/formmail.shtml http://www.iss.net/security_center/static/8012.php http://www.securityfocus.com/bid/3954 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

PGPMail.pl 1.31 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) recipient or (2) pgpuserid parameters. • http://marc.info/?l=bugtraq&m=100714269114686&w=2 http://www.securityfocus.com/archive/82/243262 •

CVSS: 7.5EPSS: 2%CPEs: 1EXPL: 0

FormMail.pl in FormMail 1.6 and earlier allows a remote attacker to send anonymous email (spam) by modifying the recipient and message parameters. • http://marc.info/?l=bugtraq&m=98433523520344&w=2 https://exchange.xforce.ibmcloud.com/vulnerabilities/6242 •