|
Family: CGI abuses --> Category: attack
Simple Form Mail Relaying Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks for Mail Relaying Vulnerability in Simple Form
Detailed Explanation for this Vulnerability Test
The target is running at least one instance of Simple Form which fails
to validate the parameters 'admin_email_to' and 'admin_email_from'.
A possible hacker, exploiting this flaw, would be able to send email through
the server (utilizing the form) to any arbitrary recipient with any
arbitrary message content. In other words, the remote host can be
used as a mail relay for things like SPAM.
See also : http://worldcommunity.com/opensource/utilities/simple_form.html
Solution : Upgrade to Simple Form 2.2 or later.
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|