Lucene search

K
nvd[email protected]NVD:CVE-2007-1898
HistoryMay 16, 2007 - 10:30 p.m.

CVE-2007-1898

2007-05-1622:30:00
web.nvd.nist.gov

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.6 Medium

AI Score

Confidence

Low

0.044 Low

EPSS

Percentile

92.4%

formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.

Affected configurations

NVD
Node
applemac_os_x
OR
hphp-ux
OR
hptru64
OR
linuxlinux_kernel
OR
microsoftwindows_2000
OR
microsoftwindows_2003_server
OR
microsoftwindows_95
OR
microsoftwindows_98gold
OR
microsoftwindows_98se
OR
microsoftwindows_me
OR
microsoftwindows_ntMatch4.0
OR
microsoftwindows_xp
OR
santa_cruz_operationsco_unix
OR
sunsolaris
OR
windriverbsdos
AND
jetboxjetbox_cmsMatch2.1

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.6 Medium

AI Score

Confidence

Low

0.044 Low

EPSS

Percentile

92.4%