FormMail Recipient CGI Variable Spamming Vulnerability

Solution:
A SourceForge project, entitled nms, has been started to serve as a repository for user-supplied replacements for various Matt Wright scripts. Users intent on using this software should investigate nms at the following URL:

http://nms-cgi.sourceforge.net/

Various workarounds have been suggested which address this issue from various angles. No vendor supplied fix seems to completely address this issue.

Parameshwar Babu <babuweb@mailvalley.com> has supplied a patch:


Matt Wright FormMail 1.6


 

Privacy Statement
Copyright 2010, SecurityFocus