HIGH · 9.3

CVE-2004-0259

The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the sam...

Vulnerability Description

The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Joe Lumbroso AcksFormmail.Php2.0

References

FAQ

What is CVE-2004-0259?

CVE-2004-0259 is a vulnerability with a CVSS score of 9.3 (HIGH). The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the sam...

How severe is CVE-2004-0259?

CVE-2004-0259 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0259?

Check the references section above for vendor advisories and patch information. Affected products include: Joe Lumbroso Acks Formmail.Php.