« Volver al listado

CVE-2002-2109

Estado: ModificadaAlta (7.5)—

Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2002-2109",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2002-12-31T05:00:00.000",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2002-01/0307.html",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://worldwidemart.com/scripts/formmail.shtml",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.iss.net/security_center/static/8012.php",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/3954",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2002-01/0307.html",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://worldwidemart.com/scripts/formmail.shtml",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.iss.net/security_center/static/8012.php",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/3954",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer."
    }
  ],
  "lastModified": "2026-06-16T22:00:40.310",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:matt_wright:formmail:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E030BDBE-4B0F-4FE1-8115-93E5ACEC591A"
            },
            {
              "criteria": "cpe:2.3:a:matt_wright:formmail:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2012B4FA-7A4A-4AFF-8961-2A2750B9642B"
            },
            {
              "criteria": "cpe:2.3:a:matt_wright:formmail:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8B21721-890E-498E-92F9-49C080070F45"
            },
            {
              "criteria": "cpe:2.3:a:matt_wright:formmail:1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41978011-ADC9-4F22-B2E9-7C45945BCDF5"
            },
            {
              "criteria": "cpe:2.3:a:matt_wright:formmail:1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1480C519-2325-427E-B394-2832430F611C"
            },
            {
              "criteria": "cpe:2.3:a:matt_wright:formmail:1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23BF8E39-98A9-4950-91EE-B4F4EAF7FA27"
            },
            {
              "criteria": "cpe:2.3:a:matt_wright:formmail:1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B565A52D-EA07-4603-91B7-0105E632A2EC"
            },
            {
              "criteria": "cpe:2.3:a:matt_wright:formmail:1.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C2CA3226-1F70-49A3-8415-2861C82DAF42"
            },
            {
              "criteria": "cpe:2.3:a:matt_wright:formmail:1.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E078DE78-8DD0-42F8-9E58-C7DBDB02DB60"
            },
            {
              "criteria": "cpe:2.3:a:matt_wright:formmail:1.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1301D169-6E80-4917-AD54-9F4F4D3874CA"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}