Published:2006/02/28 Last Updated:2008/05/21
JVN#65542239
Hyper NIKKI System allows unauthorized email submission
Overview
Hyper NIKKI System (hns) is web log software from the Hyper NIKKI System Project. hns allows unauthorized email submission as it does not validate inputs properly.
Products Affected
- hns-2.19.6 (hns-lite-2.19.6) and earlier
Description
Impact
An attacker could use the server to send unauthorized emails. In addition, when the server provides email service, the attacker could possibly conduct a DoS attack by generating many bounced emails.
Solution
References
JPCERT/CC Addendum
Credit
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory | |
CPNI Advisory | |
TRnotes | |
CVE | |
JVN iPedia |
JVNDB-2006-000605 |