FormMail could be used to flood servers with anonymous email
| formmail-anonymous-flooding (6242) |
Description:
Matt Wright's FormMail CGI program could allow an attacker to send anonymous email to arbitrary recipients. FormMail fails to properly indicate the IP address of the sender. A remote attacker could exploit this vulnerability by sending anonymous emails to flood the servers of arbitrary recipients.
Consequences:
Remedy:
Apply the FormMail.Pl script for this vulnerability, available from the Mailvalley Web site. See References.
References:
- BugTraq Mailing List, Mar 11 2001 - 22:06:37 CST: Re: CORRECTION to CODE: FormMail.pl can be used to send anonymous email.
- BugTraq Mailing List, Mon Jun 25 2001 - 10:24:10 CDT: Formmail.pl Exploit - Anti-Spam and security fix available.
- BugTraq Mailing List, Mon Mar 12 2001 - 04:23:17 CST: Re: CORRECTION to CODE: FormMail.pl can be used to send anonymous email.
- BugTraq Mailing List, Mon Mar 12 2001 - 04:43:02 CST: Re: CORRECTION to CODE: FormMail.pl can be used to send anonymous email.
- BugTraq Mailing List, Sat Mar 10 2001 - 11:43:43 CST: CORRECTION to CODE: FormMail.pl can be used to send anonymous email.
- BugTraq Mailing List, Sun Mar 11 2001 - 15:36:32 CST: Re: CORRECTION to CODE: FormMail.pl can be used to send anonymous email.
- BugTraq Mailing List, Wed May 10 2000 - 18:11:23 CDT: Black Watch Labs Vulnerability Alert.
- Mailvalley Web site: Anti-spam & Security fix for FormMail.pl script.
- BID-2469: FormMail Recipient CGI Variable Spamming Vulnerability
- CVE-2001-0357: FormMail.pl in FormMail 1.6 and earlier allows a remote attacker to send anonymous email (spam) by modifying the recipient and message parameters.
- OSVDB ID: 652: Matt Wright FormMail FormMail.pl Multiple Parameter Arbitrary Mail Relay
Platforms Affected:
- Matt's Script Archive FormMail 1.0 to 1.6
Reported:
Mar 10, 2001
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email ignore thisxforceignore this@ignore thisus.ignore thisibm.comignore this
