Published:2009/03/10  Last Updated:2009/03/13

JVN#84899898
MP Form Mail CGI vulnerability allows third party to gain administrative privileges

Overview

MP Form Mail CGI from futomi's CGI Cafe contains a vulnerability that allows an attacker to gain administrative privileges.

Products Affected

  • MP Form Mail CGI eCommerce Edition Ver 1.3.0 and earlier
  • MP Form Mail CGI Professional Edition Ver 3.2.2 and earlier

Description

MP Form Mail CGI from futomi's CGI Cafe is a software for sending contents entered into an HTML form via email. MP Form Mail CGI contains a vulnerability that allows an attacker to gain administrative privileges.

Impact

A remote attacker could impersonate an administrator of MP Form Mail CGI.

Solution

Update the Software
Update to the latest version according to the information provided by the vendor.
Workarounds
As a workaround to this vulnerability, change the settings in the server where the software is installed and disable access to the administrator menu until the software is updated.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Analyzed on 2009.03.10

Measures Conditions Severity
Access Required Routed - can be attacked over the Internet using packets
  • High
Authentication None - anonymous or no authentication (IP addresses do not count)
  • High
User Interaction Required None - the vulnerability can be exploited without an honest user taking any action
  • High
Exploit Complexity Low - little to no expertise and/or luck required to exploit (cross-site scripting)
  • High

Description of each analysis measures

Credit

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2009-0962
JVN iPedia JVNDB-2009-000014

Update History