CVE Vulnerabilities

CVE-2004-0259

Published: Nov 23, 2004 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.

Affected Software

Name Vendor Start Version End Version
Formmail.php Joe_lumbroso_acks 2.0 (including) 2.0 (including)
Formmail.php Joe_lumbroso_acks 5.0 (including) 5.0 (including)

References