Published:2009/04/27 Last Updated:2009/04/28
JVN#36982346
MiniBBS22 from CGI RESCUE allows unauthorized email transmission
Overview
MiniBBS22 from CGI RESCUE contains a vulnerability which allows unauthorized email transmission regardless of the configuration.
Products Affected
- MiniBBS22 v.1.00
Description
MiniBBS22 is a message board script provided by CGI RESCUE. MiniBBS22 contains a vulnerability which allows unauthorized email transmission regardless of the configuration.
Impact
A remote attacker may send any email to an arbitrary address.
Solution
Update the software
Update to the latest version according to the information provided by the vendor.
Vendor Status
References
JPCERT/CC Addendum
This vulnerability has been fixed and an updated version was released on December 13, 2008.Vulnerability Analysis by JPCERT/CC
Analyzed on 2009.04.27
Measures | Conditions | Severity |
---|---|---|
Access Required | Routed - can be attacked over the Internet using packets |
|
Authentication | None - anonymous or no authentication (IP addresses do not count) |
|
User Interaction Required | None - the vulnerability can be exploited without an honest user taking any action |
|
Exploit Complexity | Low - little to no expertise and/or luck required to exploit (cross-site scripting) |
|
Credit
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory | |
CPNI Advisory | |
TRnotes | |
CVE |
CVE-2009-1589 |
JVN iPedia |
JVNDB-2009-000021 |