Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2003-0979

Опубликовано: 05 янв. 2004
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input, which allows remote attackers to (1) use VisitorBook as an open mail relay, when $mailuser is 1, via extra headers in the email field, or (2) cause the guestbook database to be deleted via a large number of line breaks that exceeds the $max_posts variable.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:freescripts:visitorbook:le:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.00482
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input, which allows remote attackers to (1) use VisitorBook as an open mail relay, when $mailuser is 1, via extra headers in the email field, or (2) cause the guestbook database to be deleted via a large number of line breaks that exceeds the $max_posts variable.

EPSS

Процентиль: 65%
0.00482
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other