Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Biz Mail Form Unauthorized Mail Relay Vulnerability

Biz Mail Form is prone to a vulnerability that allows the application to be abused as a mail relay.

An attacker can exploit this issue to inject arbitrary SMTP headers by using CR and LF sequences.

If successful, it becomes possible to abuse the application as a mail relay. Email may be sent to arbitrary computers. This could be exploited by spammers or other malicious parties.

Update: It is reported that the update to address this issue (Biz Mail Form 2.2) is vulnerable to this issue as well. The affected version is being added as a vulnerable package and the fixes are being removed.







 

Privacy Statement
Copyright 2008, SecurityFocus